CVE-2025-32754·Docker vulnerability
In jenkins/ssh-agent Docker images 6.11.1 and earlier, SSH host keys are generated on image creation for images based on Debian, causing all containers based on images of the same version use the same SSH host keys, allowing attackers able to insert themselves into the network path between the SSH client (typically the Jenkins controller) and SSH build agent to impersonate the latter.
- Severity
- critical
- Software
- Docker
- Fixed in
- 6.11.2
- Published
- 2025-04-10
Affected versions
Until: 6.11.2
Fixed in: 6.11.2
How to fix this CVE
Upgrade Docker to version 6.11.2 or later to remediate the SSH host key generation vulnerability in jenkins/ssh-agent images. This fix ensures that SSH host keys are dynamically generated at container runtime rather than baked into the image, preventing key reuse across multiple container instances. Organizations running Jenkins SSH build agents should prioritize this update to eliminate the risk of man-in-the-middle attacks between Jenkins controllers and remote agents.
sudo dnf update docker-ceDefensia detects this vulnerability
How to check if you are affected
- Run `docker --version` to check your current Docker installation version
- Execute `docker images | grep ssh-agent` to list all jenkins/ssh-agent images present on the system
- For each image, run `docker image inspect {image_id} | grep -i version` to confirm the image tag and verify it is version 6.11.2 or later
- Verify the fix by pulling the latest jenkins/ssh-agent image and comparing SSH host keys generated in containers from old vs. new images using `ssh-keyscan` against running containers
FAQ
What is CVE-2025-32754?
CVE-2025-32754 is a critical vulnerability in jenkins/ssh-agent Docker images where SSH host keys are generated at image build time rather than at container runtime, causing all containers derived from the same image to share identical host keys. This allows attackers positioned on the network to impersonate SSH agents and intercept communications with the Jenkins controller.
Is CVE-2025-32754 being actively exploited?
No, CVE-2025-32754 is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and no public exploits are currently available, though the attack vector is straightforward for adversaries with network access.
What versions of Docker are affected by CVE-2025-32754?
jenkins/ssh-agent Docker images version 6.11.1 and earlier are affected. Version 6.11.2 and later contain the remediation.
How do I check if my server is vulnerable to CVE-2025-32754?
Run `docker images | grep ssh-agent` and check the image tags. If any images are tagged with version 6.11.1 or lower, your deployment is vulnerable. Confirm with `docker image inspect {image_id}` to verify the exact version metadata.
Does Defensia detect CVE-2025-32754?
Yes — Defensia's CVE advisory scanner compares installed Docker image versions against the NVD database. If vulnerable jenkins/ssh-agent images are present on monitored servers, CVE-2025-32754 will appear in your dashboard with remediation steps.
Related Docker CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2025-32754. Free for 1 server.
Get started free