Логотип exploitDog
bind:CVE-2025-32754
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-32754

Количество 3

Количество 3

nvd логотип

CVE-2025-32754

10 месяцев назад

In jenkins/ssh-agent Docker images 6.11.1 and earlier, SSH host keys are generated on image creation for images based on Debian, causing all containers based on images of the same version use the same SSH host keys, allowing attackers able to insert themselves into the network path between the SSH client (typically the Jenkins controller) and SSH build agent to impersonate the latter.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-x97h-g784-4pw8

10 месяцев назад

In jenkins/ssh-agent Docker images 6.11.1 and earlier, SSH host keys are generated on image creation for images based on Debian, causing all containers based on images of the same version use the same SSH host keys, allowing attackers able to insert themselves into the network path between the SSH client (typically the Jenkins controller) and SSH build agent to impersonate the latter.

CVSS3: 9.1
EPSS: Низкий
fstec логотип

BDU:2025-04588

10 месяцев назад

Уязвимость SSH-клиента ssh-agent сервера автоматизации Jenkins, связанная с ошибками в коде генератора псевдослучайных чисел при генерации ключей хоста, позволяющая нарушителю реализовать атаку типа «человек посередине»

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-32754

In jenkins/ssh-agent Docker images 6.11.1 and earlier, SSH host keys are generated on image creation for images based on Debian, causing all containers based on images of the same version use the same SSH host keys, allowing attackers able to insert themselves into the network path between the SSH client (typically the Jenkins controller) and SSH build agent to impersonate the latter.

CVSS3: 9.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-x97h-g784-4pw8

In jenkins/ssh-agent Docker images 6.11.1 and earlier, SSH host keys are generated on image creation for images based on Debian, causing all containers based on images of the same version use the same SSH host keys, allowing attackers able to insert themselves into the network path between the SSH client (typically the Jenkins controller) and SSH build agent to impersonate the latter.

CVSS3: 9.1
0%
Низкий
10 месяцев назад
fstec логотип
BDU:2025-04588

Уязвимость SSH-клиента ssh-agent сервера автоматизации Jenkins, связанная с ошибками в коде генератора псевдослучайных чисел при генерации ключей хоста, позволяющая нарушителю реализовать атаку типа «человек посередине»

CVSS3: 9.1
0%
Низкий
10 месяцев назад

Уязвимостей на страницу