CVE-2025-1696 - CVE House
Back to Database
Status published Medium CVE-2025-1696

Exposure of Proxy Credentials in Docker Desktop Logs

Vulnerability Description

A vulnerability exists in Docker Desktop prior to version 4.39.0 that could lead to the unintentional disclosure of sensitive information via application logs. In affected versions, proxy configuration data—potentially including sensitive details—was written to log files in clear text whenever an HTTP GET request was made through a proxy. An attacker with read access to these logs could obtain the proxy information and leverage it for further attacks or unauthorized access. Starting with version 4.39.0, Docker Desktop no longer logs the proxy string, thereby mitigating this risk.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-1696

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Docker Desktop
Vulnerable Versions:
0

Timeline

Official Publish: March 6th, 2025
Last Modified: March 6th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)