In jenkins/ssh-slave Docker images based on Debian, SSH host keys are generated on image creation for images based on Debian, causing all containers based on images of the same version use the same SSH host keys, allowing attackers able to insert themselves into the network path between the SSH client (typically the Jenkins controller) and SSH build agent to impersonate the latter.
                
            References
                    | Link | Resource | 
|---|---|
| https://www.jenkins.io/security/advisory/2025-04-10/#SECURITY-3565 | Vendor Advisory | 
Configurations
                    History
                    02 May 2025, 15:54
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://www.jenkins.io/security/advisory/2025-04-10/#SECURITY-3565 - Vendor Advisory | |
| CPE | cpe:2.3:a:jenkins:ssh-slave:*:*:*:*:*:docker:*:* | |
| First Time | Jenkins Jenkins ssh-slave | 
11 Apr 2025, 15:39
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
 | 
10 Apr 2025, 14:15
| Type | Values Removed | Values Added | 
|---|---|---|
| CWE | CWE-338 | |
| CVSS | v2 : v3 : | v2 : unknown v3 : 9.1 | 
10 Apr 2025, 12:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-04-10 12:15
Updated : 2025-05-02 15:54
NVD link : CVE-2025-32755
Mitre link : CVE-2025-32755
CVE.ORG link : CVE-2025-32755
JSON object : View
Products Affected
                jenkins
- ssh-slave
CWE
                
                    
                        
                        CWE-338
                        
            Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
