From 17a014474ec0fd9f60bf423487363780dfe45d15 Mon Sep 17 00:00:00 2001 From: Bruno Sousa <107440821+bsousaa@users.noreply.github.com> Date: Tue, 29 Apr 2025 19:30:09 +0100 Subject: [PATCH] Add CVE-2025-4095 to release notes of Docker Desktop 4.41 --- content/manuals/desktop/release-notes.md | 1 + 1 file changed, 1 insertion(+) diff --git a/content/manuals/desktop/release-notes.md b/content/manuals/desktop/release-notes.md index 986e9ba778ef..58345bd57e87 100644 --- a/content/manuals/desktop/release-notes.md +++ b/content/manuals/desktop/release-notes.md @@ -54,6 +54,7 @@ For more frequently asked questions, see the [FAQs](/manuals/desktop/troubleshoo ### Security - Fixed [CVE-2025-3224](https://www.cve.org/CVERecord?id=CVE-2025-3224) allowing an attacker with access to a user machine to perform an elevation of privilege when Docker Desktop updates. +- Fixed [CVE-2025-4095](https://www.cve.org/CVERecord?id=CVE-2025-4095) where Registry Access Management (RAM) policies were not enforced when using a MacOS configuration profile, allowing users to pull images from unapproved registries. ### Bug fixes and enhancements