CVE Vulnerabilities

CVE-2025-13743

Insertion of Sensitive Information into Log File

Published: Dec 09, 2025 | Modified: Dec 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Docker Desktop diagnostics bundles were found to include expired Hub PATs in log output due to error object serialization. This poses a risk of leaking sensitive information in exported diagnostics, especially when access denied errors occurred.

Weakness

The product writes sensitive information to a log file.

Potential Mitigations

References