🛡️ SUSE-SU-2025:20385-1 — docker-compose (CVE-2023-47108)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for docker-compose

This update for docker-compose fixes the following issues:

Update to version 2.33.1:

  • Improvements
  • Add support for gw_priority, enable_ipv4 (requires docker

v28.0) by @thaJeztah in #12570

  • Fixes
  • Run watch standalone if menu fails to start by @ndeloof in

#12536

  • Report error using non-file secret|config with read-only

service by @ndeloof in #12531

  • Don't display bake suggestion when using --progress with

quiet or json option by @glours in #12561

  • Fix pull --parallel and --no-parallel deprecation warnings

missing by @maxproske in #12555

  • Fix error message when detach is implied by wait by @ndeloof

in #12566

  • Dependencies
  • build(deps): bump github.com/spf13/cobra from 1.8.1 to 1.9.1

by @dependabot in #12556

  • build(deps): bump google.golang.org/grpc from 1.68.1 to

1.70.0 by @dependabot in #12494

  • go.mod: update to docker v28.0.0 by @thaJeztah in #12545

Update to version 2.33.0:

  • Important
  • This release introduce support for Bake to manage builds as

an alternative to the internal buildkit client. This new

feature can be enabled by setting COMPOSE_BAKE=1 variable.

Bake will become the default builder in a future release.

  • Improvements
  • let user know bake is now supported by @ndeloof in #12524
  • support additional_context reference to another service by

@ndeloof in #12485

  • add support for BUILDKIT_PROGRESS by @ndeloof in #12458
  • add --with-env flag to publish command by @glours in #12482
  • Update ls --quiet help description by @maxproske in #12541
  • Publish warn display env vars by @glours in #12486
  • Fixes
  • Fix bake support by @ndeloof in #12507
  • Update link in stats --help output by @maxproske in #12523
  • Properly handle "builtin" seccomp profile by @r-bk in #12478
  • manage watch applied to mulitple services by @ndeloof in

#12469

  • Internal
  • use main branch for docs upstream validation workflow by

@crazy-max in #12487

  • fix provenance for binaries and generate sbom by @crazy-max

in #12479

  • add codeowners file by @glours in #12480
  • remove exit code per error type used by legacy metrics system

by @ndeloof in #12502

  • Dockerfile: update golangci-lint to v1.63.4 by @thaJeztah in

#12546

  • Full test coverage for compatibility cmd by @maxproske in

#12528

  • don't send raw os.Args to opentelemetry but a pseudo command

line by @ndeloof in #12530

  • add docker engine v28.x to the test-matrix by @thaJeztah in

#12539

  • enable copyloopvar linter by @thaJeztah in #12542
  • go.mod: remove toolchain directive by @thaJeztah in #12551
  • Dependencies
  • bump buildx v0.20.1 by @ndeloof in #12488
  • bump docker to v27.5.1 by @ndeloof in #12491
  • bump compose-go v2.4.8 by @ndeloof in #12543
  • bump golang.org/x/sys from 0.28.0 to 0.30.0 by @dependabot in

#12529

  • bump github.com/moby/term v0.5.2 by @thaJeztah in #12540
  • bump github.com/otiai10/copy from 1.14.0 to 1.14.1 by

@dependabot in #12493

  • bump github.com/jonboulle/clockwork from 0.4.0 to 0.5.0 by

@dependabot in #12430

  • bump github.com/spf13/pflag from 1.0.5 to 1.0.6 by

@dependabot in #12548

  • bump golang.org/x/sync from 0.10.0 to 0.11.0 by @dependabot

in #12547

  • bump gotest.tools/v3 from 3.5.1 to 3.5.2 by @dependabot in

#12549

Update to version 2.32.4:

  • add missing tag for build during merge workflow
  • ci: re-use local source to build binary images
  • ci: use local source for binary builds

Update to version 2.32.3:

  • ci: update bake-action to v6
  • simplification
  • image can be set to a local ID, that isn't a valid docker ref
  • can't render progress concurrently with buildkit
  • exclude one-off container running convergence
  • Only override service mac if set on the main network.

Update to version 2.32.2:

  • remove engine v25 from e2e test matrix The 1st version

available for Ubuntu 24.x is Docker Engine v26

  • fix relative path in compose file
  • bump compose-go to v2.4.7
  • replace tibdex/github-app-token by official GitHub

create-github-app-token

  • bump golang.org/x/net to v0.33.0 to fix potential security

issue https://github.com/golang/go/issues/70906

  • checkExpectedVolumes must ignore anonymous volumes
  • When retrying to resolveOrCreateNetwork, retry with a valid

network name

  • only check bind mount conflict if sync action is involved
  • use the 3 latest major versions of the engine to run e2e step
  • bump Golang version to v1.22.10 and update CI actions
  • add --pull to run command
  • CI to validate fmt
  • make fmt so any contributor can enforce formatting
  • format code with gofumpt

Update to version 2.32.1:

  • e2e test to prevent future regression
  • only check volume mounts for updated config

Update to ve

Affected software

SUSE-SU-2025:20385-1 is recorded against 1 package.

  • docker-compose (fixed in 2.33.1-1.1)

Timeline and source

Published on 10 June 2025 and last revised on 23 March 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
www.suse.com (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2025-06-10
Updated 2026-08-20
Modified 2026-03-23
Fix URL N/A

Affected Packages

Software From version Fixed in
docker-compose 2.33.1-1.1

Similar Threats

Free Vulnerability Check

Is your site affected by SUSE-SU-2025:20385-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2025:20385-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesSUSESUSE 2025