Vulnerability Description
The Docker image from acme.sh before 40b6db6 is based on a .github/workflows/dockerhub.yml file that lacks "persist-credentials: false" for actions/checkout.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/acmesh-official/acme.sh/commit/40b6db6a2715628aa977ed1853fe52
- https://github.com/acmesh-official/acme.sh/commit/a1de13657e79c5471dbc8fa3539ea3
- https://github.com/actions/checkout/blob/85e6279cec87321a52edac9c87bce653a07cf6c
FAQ
What is CVE-2025-32111?
CVE-2025-32111 is a vulnerability with a CVSS score of 8.7 (HIGH). The Docker image from acme.sh before 40b6db6 is based on a .github/workflows/dockerhub.yml file that lacks "persist-credentials: false" for actions/checkout.
How severe is CVE-2025-32111?
CVE-2025-32111 has been rated HIGH with a CVSS base score of 8.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-32111?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.