CVE-2025-32111
CVSS 3.1 Score 8.7 of 10 (high)
Details
Published Apr 4, 2025
Updated: Apr 7, 2025
CWE ID 260
Summary
CVE-2025-32111 is a vulnerability affecting acme.sh's Docker image before 40b6db6. The issue lies in the .github/workflows/dockerhub.yml file, which fails to include "persist-credentials: false" for the "actions/checkout" action. Consequently, sensitive information, such as credentials, may be inadvertently persisted, leading to potential unauthorized access. This vulnerability underscores the importance of securely managing credentials within GitHub Actions workflows.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.