VYPR

Docker Desktop installer

by Docker

CVEs (25)

  • CVE-2021-45449MedJan 12, 2022
    risk 0.36cvss 5.5epss 0.00

    Docker Desktop version 4.3.0 and 4.3.1 has a bug that may log sensitive information (access token or password) on the user's machine during login. This only affects users if they are on Docker Desktop 4.3.0, 4.3.1 and the user has logged in while on 4.3.0, 4.3.1. Gaining access…

  • CVE-2022-23774MedFeb 1, 2022
    risk 0.35cvss 5.3epss 0.01

    Docker Desktop before 4.4.4 on Windows allows attackers to move arbitrary files.

  • CVE-2025-6587MedJul 3, 2025
    risk 0.34cvss epss 0.00

    System environment variables are recorded in Docker Desktop diagnostic logs, when using shell auto-completion. This leads to unintentional disclosure of sensitive information such as api keys, passwords, etc.  A malicious actor with read access to these logs could obtain…

  • CVE-2025-3911MedApr 29, 2025
    risk 0.34cvss epss 0.00

    Recording of environment variables, configured for running containers, in Docker Desktop application logs could lead to unintentional disclosure of sensitive information such as api keys, passwords, etc. A malicious actor with read access to these logs could obtain sensitive…

  • CVE-2025-1696MedMar 6, 2025
    risk 0.34cvss epss 0.00

    A vulnerability exists in Docker Desktop prior to version 4.39.0 that could lead to the unintentional disclosure of sensitive information via application logs. In affected versions, proxy configuration data—potentially including sensitive details—was written to log files in…

Page 2 of 2