Логотип exploitDog
bind: "CVE-2025-62725"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2025-62725"

Количество 6

Количество 6

ubuntu логотип

CVE-2025-62725

3 месяца назад

Docker Compose trusts the path information embedded in remote OCI compose artifacts. When a layer includes the annotations com.docker.compose.extends or com.docker.compose.envfile, Compose joins the attacker‑supplied value from com.docker.compose.file/com.docker.compose.envfile with its local cache directory and writes the file there. This affects any platform or workflow that resolves remote OCI compose artifacts, Docker Desktop, standalone Compose binaries on Linux, CI/CD runners, cloud dev environments is affected. An attacker can escape the cache directory and overwrite arbitrary files on the machine running docker compose, even if the user only runs read‑only commands such as docker compose config or docker compose ps. This issue is fixed in v2.40.2.

EPSS: Низкий
nvd логотип

CVE-2025-62725

3 месяца назад

Docker Compose trusts the path information embedded in remote OCI compose artifacts. When a layer includes the annotations com.docker.compose.extends or com.docker.compose.envfile, Compose joins the attacker‑supplied value from com.docker.compose.file/com.docker.compose.envfile with its local cache directory and writes the file there. This affects any platform or workflow that resolves remote OCI compose artifacts, Docker Desktop, standalone Compose binaries on Linux, CI/CD runners, cloud dev environments is affected. An attacker can escape the cache directory and overwrite arbitrary files on the machine running docker compose, even if the user only runs read‑only commands such as docker compose config or docker compose ps. This issue is fixed in v2.40.2.

EPSS: Низкий
debian логотип

CVE-2025-62725

3 месяца назад

Docker Compose trusts the path information embedded in remote OCI comp ...

EPSS: Низкий
github логотип

GHSA-gv8h-7v7w-r22q

3 месяца назад

Docker Compose Vulnerable to Path Traversal via OCI Artifact Layer Annotations

EPSS: Низкий
fstec логотип

BDU:2025-14002

3 месяца назад

Уязвимость инструмента для управления многоконтейнерными приложениями Docker Compose, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю перезаписать произвольные файлы

CVSS3: 8.8
EPSS: Низкий
redos логотип

ROS-20251113-08

2 месяца назад

Уязвимость docker-compose

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-62725

Docker Compose trusts the path information embedded in remote OCI compose artifacts. When a layer includes the annotations com.docker.compose.extends or com.docker.compose.envfile, Compose joins the attacker‑supplied value from com.docker.compose.file/com.docker.compose.envfile with its local cache directory and writes the file there. This affects any platform or workflow that resolves remote OCI compose artifacts, Docker Desktop, standalone Compose binaries on Linux, CI/CD runners, cloud dev environments is affected. An attacker can escape the cache directory and overwrite arbitrary files on the machine running docker compose, even if the user only runs read‑only commands such as docker compose config or docker compose ps. This issue is fixed in v2.40.2.

0%
Низкий
3 месяца назад
nvd логотип
CVE-2025-62725

Docker Compose trusts the path information embedded in remote OCI compose artifacts. When a layer includes the annotations com.docker.compose.extends or com.docker.compose.envfile, Compose joins the attacker‑supplied value from com.docker.compose.file/com.docker.compose.envfile with its local cache directory and writes the file there. This affects any platform or workflow that resolves remote OCI compose artifacts, Docker Desktop, standalone Compose binaries on Linux, CI/CD runners, cloud dev environments is affected. An attacker can escape the cache directory and overwrite arbitrary files on the machine running docker compose, even if the user only runs read‑only commands such as docker compose config or docker compose ps. This issue is fixed in v2.40.2.

0%
Низкий
3 месяца назад
debian логотип
CVE-2025-62725

Docker Compose trusts the path information embedded in remote OCI comp ...

0%
Низкий
3 месяца назад
github логотип
GHSA-gv8h-7v7w-r22q

Docker Compose Vulnerable to Path Traversal via OCI Artifact Layer Annotations

0%
Низкий
3 месяца назад
fstec логотип
BDU:2025-14002

Уязвимость инструмента для управления многоконтейнерными приложениями Docker Compose, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю перезаписать произвольные файлы

CVSS3: 8.8
0%
Низкий
3 месяца назад
redos логотип
ROS-20251113-08

Уязвимость docker-compose

CVSS3: 8.8
0%
Низкий
2 месяца назад

Уязвимостей на страницу