Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-54388

Опубликовано: 30 июл. 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 4.6

Описание

Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. In versions 28.2.0 through 28.3.2, when the firewalld service is reloaded it removes all iptables rules including those created by Docker. While Docker should automatically recreate these rules, versions before 28.3.3 fail to recreate the specific rules that block external access to containers. This means that after a firewalld reload, containers with ports published to localhost (like 127.0.0.1:8080) become accessible from remote machines that have network routing to the Docker bridge, even though they should only be accessible from the host itself. The vulnerability only affects explicitly published ports - unpublished ports remain protected. This issue is fixed in version 28.3.3.

РелизСтатусПримечание
devel

needs-triage

esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

esm-apps/resolute

needs-triage

esm-infra-legacy/xenial

needs-triage

esm-infra/xenial

ignored

end of ESM support, was needs-triage
jammy

needs-triage

noble

needs-triage

Показывать по

РелизСтатусПримечание
devel

not-affected

29.1.3-0ubuntu4
esm-apps/focal

not-affected

code not present
esm-apps/jammy

needed

esm-apps/noble

needed

esm-apps/resolute

needed

jammy

needed

noble

needed

plucky

ignored

end of life, was needed
questing

ignored

end of life, was needed
resolute

needed

Показывать по

EPSS

Процентиль: 12%
0.00215
Низкий

4.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.2
redhat
около 1 года назад

Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. In versions 28.2.0 through 28.3.2, when the firewalld service is reloaded it removes all iptables rules including those created by Docker. While Docker should automatically recreate these rules, versions before 28.3.3 fail to recreate the specific rules that block external access to containers. This means that after a firewalld reload, containers with ports published to localhost (like 127.0.0.1:8080) become accessible from remote machines that have network routing to the Docker bridge, even though they should only be accessible from the host itself. The vulnerability only affects explicitly published ports - unpublished ports remain protected. This issue is fixed in version 28.3.3.

CVSS3: 4.6
nvd
около 1 года назад

Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. In versions 28.2.0 through 28.3.2, when the firewalld service is reloaded it removes all iptables rules including those created by Docker. While Docker should automatically recreate these rules, versions before 28.3.3 fail to recreate the specific rules that block external access to containers. This means that after a firewalld reload, containers with ports published to localhost (like 127.0.0.1:8080) become accessible from remote machines that have network routing to the Docker bridge, even though they should only be accessible from the host itself. The vulnerability only affects explicitly published ports - unpublished ports remain protected. This issue is fixed in version 28.3.3.

CVSS3: 4.6
debian
около 1 года назад

Moby is an open source container framework developed by Docker Inc. th ...

suse-cvrf
6 месяцев назад

Security update for docker

suse-cvrf
12 месяцев назад

Security update for docker

EPSS

Процентиль: 12%
0.00215
Низкий

4.6 Medium

CVSS3