Impact
Docker Sandboxes can improperly reveal credential data when a response-body read returns data in the presence of an error. The affected handlers may forward unmasked bytes, allowing code running in an authorized sandbox to capture host‑managed OAuth access and refresh tokens or a derived API key that was intended to remain outside the sandbox. The result is the disclosure of privileged credentials that can be used to authenticate against host resources and external services, potentially enabling further compromise or unauthorized access.
Affected Systems
All Docker Sandboxes installations prior to 0.47.0 are affected. The vulnerability exists in the Docker Sandboxes platform and manifests when sandboxed code interacts with proxy responses that contain credential information.
Risk and Exploitability
The CVSS score of 5.9 indicates a moderate impact. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Since the flaw is accessed from within an authorized sandbox, the attack vector requires the ability to execute code inside the sandbox or supply crafted sandboxed input. An attacker who succeeds can obtain host‑level OAuth tokens or API keys, which can be leveraged for unauthorized API access or to move laterally into the host environment. The likelihood of exploitation is limited to scenarios where a sandboxed deployment is used with proxy‑managed credentials, but once the vulnerability is known it poses a significant risk to credential confidentiality.
OpenCVE Enrichment