Host key reuse in Jenkins ssh-agent Docker images



Risk Medium
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2025-32754
CWE-ID CWE-323
Exploitation vector Network
Public exploit N/A
Vulnerable software
ssh-agent Docker images
Web applications / Modules and components for CMS

Vendor Jenkins

Security Bulletin

This security bulletin contains one medium risk vulnerability.

1) Reusing a Nonce, Key Pair in Encryption

EUVDB-ID: #VU107445

Risk: Medium

CVSSv4.0: 1.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2025-32754

CWE-ID: CWE-323 - Reusing a Nonce, Key Pair in Encryption

Exploit availability: No

Description

The vulnerability allows a remote attacker to compromise the target system. 

The vulnerability exists due to SSH host keys are generated on image creation for images based on Debian. A remote attacker can insert themselves into the network path between the SSH client and SSH build agent to impersonate the latter.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

ssh-agent Docker images: 6.0.0 - 6.11.1

CPE2.3 External links

https://www.jenkins.io/security/advisory/2025-04-10/#SECURITY-3565


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###