CVE-2025-32755
Published: Apr 10, 2025
Modified: Apr 10, 2025
Description
In jenkins/ssh-slave Docker images based on Debian, SSH host keys are generated on image creation for images based on Debian, causing all containers based on images of the same version use the same SSH host keys, allowing attackers able to insert themselves into the network path between the SSH client (typically the Jenkins controller) and SSH build agent to impersonate the latter.
| Vendor | Product | Versions |
|---|---|---|
Jenkins Project | Jenkins jenkins/ssh-slave Docker images | unaffected alpine |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now