CVE-2025-36154

IBM Concert 1.0.0 through 2.1.0 stores sensitive information in cleartext during recursive docker builds which could be obtained by a local user.

medium 6.2 CVSS 3.1
Published: Dec 24, 2025
Modified: Dec 30, 2025
Vendor: Ibm
Product: Concert

Description

IBM Concert 1.0.0 through 2.1.0 stores sensitive information in cleartext during recursive docker builds which could be obtained by a local user.

References

Related CVEs