Логотип exploitDog
bind:"BDU:2025-14002" OR bind:"CVE-2025-62725"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2025-14002" OR bind:"CVE-2025-62725"

Количество 8

Количество 8

fstec логотип

BDU:2025-14002

5 месяцев назад

Уязвимость инструмента для управления многоконтейнерными приложениями Docker Compose, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю перезаписать произвольные файлы

CVSS3: 8.8
EPSS: Низкий
redos логотип

ROS-20251113-08

5 месяцев назад

Уязвимость docker-compose

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2025-62725

5 месяцев назад

Docker Compose trusts the path information embedded in remote OCI compose artifacts. When a layer includes the annotations com.docker.compose.extends or com.docker.compose.envfile, Compose joins the attacker‑supplied value from com.docker.compose.file/com.docker.compose.envfile with its local cache directory and writes the file there. This affects any platform or workflow that resolves remote OCI compose artifacts, Docker Desktop, standalone Compose binaries on Linux, CI/CD runners, cloud dev environments is affected. An attacker can escape the cache directory and overwrite arbitrary files on the machine running docker compose, even if the user only runs read‑only commands such as docker compose config or docker compose ps. This issue is fixed in v2.40.2.

EPSS: Низкий
redhat логотип

CVE-2025-62725

5 месяцев назад

Docker Compose trusts the path information embedded in remote OCI compose artifacts. When a layer includes the annotations com.docker.compose.extends or com.docker.compose.envfile, Compose joins the attacker‑supplied value from com.docker.compose.file/com.docker.compose.envfile with its local cache directory and writes the file there. This affects any platform or workflow that resolves remote OCI compose artifacts, Docker Desktop, standalone Compose binaries on Linux, CI/CD runners, cloud dev environments is affected. An attacker can escape the cache directory and overwrite arbitrary files on the machine running docker compose, even if the user only runs read‑only commands such as docker compose config or docker compose ps. This issue is fixed in v2.40.2.

CVSS3: 8
EPSS: Низкий
nvd логотип

CVE-2025-62725

5 месяцев назад

Docker Compose trusts the path information embedded in remote OCI compose artifacts. When a layer includes the annotations com.docker.compose.extends or com.docker.compose.envfile, Compose joins the attacker‑supplied value from com.docker.compose.file/com.docker.compose.envfile with its local cache directory and writes the file there. This affects any platform or workflow that resolves remote OCI compose artifacts, Docker Desktop, standalone Compose binaries on Linux, CI/CD runners, cloud dev environments is affected. An attacker can escape the cache directory and overwrite arbitrary files on the machine running docker compose, even if the user only runs read‑only commands such as docker compose config or docker compose ps. This issue is fixed in v2.40.2.

EPSS: Низкий
debian логотип

CVE-2025-62725

5 месяцев назад

Docker Compose trusts the path information embedded in remote OCI comp ...

EPSS: Низкий
github логотип

GHSA-gv8h-7v7w-r22q

5 месяцев назад

Docker Compose Vulnerable to Path Traversal via OCI Artifact Layer Annotations

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20438-1

8 дней назад

Security update for docker-compose

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2025-14002

Уязвимость инструмента для управления многоконтейнерными приложениями Docker Compose, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю перезаписать произвольные файлы

CVSS3: 8.8
0%
Низкий
5 месяцев назад
redos логотип
ROS-20251113-08

Уязвимость docker-compose

CVSS3: 8.8
0%
Низкий
5 месяцев назад
ubuntu логотип
CVE-2025-62725

Docker Compose trusts the path information embedded in remote OCI compose artifacts. When a layer includes the annotations com.docker.compose.extends or com.docker.compose.envfile, Compose joins the attacker‑supplied value from com.docker.compose.file/com.docker.compose.envfile with its local cache directory and writes the file there. This affects any platform or workflow that resolves remote OCI compose artifacts, Docker Desktop, standalone Compose binaries on Linux, CI/CD runners, cloud dev environments is affected. An attacker can escape the cache directory and overwrite arbitrary files on the machine running docker compose, even if the user only runs read‑only commands such as docker compose config or docker compose ps. This issue is fixed in v2.40.2.

0%
Низкий
5 месяцев назад
redhat логотип
CVE-2025-62725

Docker Compose trusts the path information embedded in remote OCI compose artifacts. When a layer includes the annotations com.docker.compose.extends or com.docker.compose.envfile, Compose joins the attacker‑supplied value from com.docker.compose.file/com.docker.compose.envfile with its local cache directory and writes the file there. This affects any platform or workflow that resolves remote OCI compose artifacts, Docker Desktop, standalone Compose binaries on Linux, CI/CD runners, cloud dev environments is affected. An attacker can escape the cache directory and overwrite arbitrary files on the machine running docker compose, even if the user only runs read‑only commands such as docker compose config or docker compose ps. This issue is fixed in v2.40.2.

CVSS3: 8
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2025-62725

Docker Compose trusts the path information embedded in remote OCI compose artifacts. When a layer includes the annotations com.docker.compose.extends or com.docker.compose.envfile, Compose joins the attacker‑supplied value from com.docker.compose.file/com.docker.compose.envfile with its local cache directory and writes the file there. This affects any platform or workflow that resolves remote OCI compose artifacts, Docker Desktop, standalone Compose binaries on Linux, CI/CD runners, cloud dev environments is affected. An attacker can escape the cache directory and overwrite arbitrary files on the machine running docker compose, even if the user only runs read‑only commands such as docker compose config or docker compose ps. This issue is fixed in v2.40.2.

0%
Низкий
5 месяцев назад
debian логотип
CVE-2025-62725

Docker Compose trusts the path information embedded in remote OCI comp ...

0%
Низкий
5 месяцев назад
github логотип
GHSA-gv8h-7v7w-r22q

Docker Compose Vulnerable to Path Traversal via OCI Artifact Layer Annotations

0%
Низкий
5 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20438-1

Security update for docker-compose

8 дней назад

Уязвимостей на страницу