CVE-2025-32111 Details
Description
The Docker image from acme.sh before 40b6db6 is based on a .github/workflows/dockerhub.yml file that lacks "persist-credentials: false" for actions/checkout.
A vulnerability exists in the Docker image from acme.sh, prior to the commit 40b6db6, which is based on a workflow file for GitHub Actions. The vulnerability arises because the workflow file does not include the 'persist-credentials: false' option for the actions/checkout step. This omission can lead to unintended credential persistence, potentially allowing for credential leakage or misuse.
Users can update to the acme.sh Docker image version that includes the necessary credential management. Instructions for building the Docker image with the correct configuration are available in the acme.sh repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 4, 2025CISA-ADP
Assessed Apr 4, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-260 | Password in Configuration File | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| acme.sh | < 40b6db6 |
CPE
Remediation
| |
| actions/checkout | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 4, 2025 | New CVE Received | [email protected] |
Volerion