🛡️ SUSE-SU-2025:20385-1 — docker-compose (CVE-2023-47108)
Description
Security update for docker-compose
This update for docker-compose fixes the following issues:
Update to version 2.33.1:
- Improvements
- Add support for gw_priority, enable_ipv4 (requires docker
v28.0) by @thaJeztah in #12570
- Fixes
- Run watch standalone if menu fails to start by @ndeloof in
#12536
- Report error using non-file secret|config with read-only
service by @ndeloof in #12531
- Don't display bake suggestion when using --progress with
quiet or json option by @glours in #12561
- Fix pull --parallel and --no-parallel deprecation warnings
missing by @maxproske in #12555
- Fix error message when detach is implied by wait by @ndeloof
in #12566
- Dependencies
- build(deps): bump github.com/spf13/cobra from 1.8.1 to 1.9.1
by @dependabot in #12556
- build(deps): bump google.golang.org/grpc from 1.68.1 to
1.70.0 by @dependabot in #12494
- go.mod: update to docker v28.0.0 by @thaJeztah in #12545
Update to version 2.33.0:
- Important
- This release introduce support for Bake to manage builds as
an alternative to the internal buildkit client. This new
feature can be enabled by setting COMPOSE_BAKE=1 variable.
Bake will become the default builder in a future release.
- Improvements
- let user know bake is now supported by @ndeloof in #12524
- support additional_context reference to another service by
@ndeloof in #12485
- add support for BUILDKIT_PROGRESS by @ndeloof in #12458
- add --with-env flag to publish command by @glours in #12482
- Update ls --quiet help description by @maxproske in #12541
- Publish warn display env vars by @glours in #12486
- Fixes
- Fix bake support by @ndeloof in #12507
- Update link in stats --help output by @maxproske in #12523
- Properly handle "builtin" seccomp profile by @r-bk in #12478
- manage watch applied to mulitple services by @ndeloof in
#12469
- Internal
- use main branch for docs upstream validation workflow by
@crazy-max in #12487
- fix provenance for binaries and generate sbom by @crazy-max
in #12479
- add codeowners file by @glours in #12480
- remove exit code per error type used by legacy metrics system
by @ndeloof in #12502
- Dockerfile: update golangci-lint to v1.63.4 by @thaJeztah in
#12546
- Full test coverage for compatibility cmd by @maxproske in
#12528
- don't send raw os.Args to opentelemetry but a pseudo command
line by @ndeloof in #12530
- add docker engine v28.x to the test-matrix by @thaJeztah in
#12539
- enable copyloopvar linter by @thaJeztah in #12542
- go.mod: remove toolchain directive by @thaJeztah in #12551
- Dependencies
- bump buildx v0.20.1 by @ndeloof in #12488
- bump docker to v27.5.1 by @ndeloof in #12491
- bump compose-go v2.4.8 by @ndeloof in #12543
- bump golang.org/x/sys from 0.28.0 to 0.30.0 by @dependabot in
#12529
- bump github.com/moby/term v0.5.2 by @thaJeztah in #12540
- bump github.com/otiai10/copy from 1.14.0 to 1.14.1 by
@dependabot in #12493
- bump github.com/jonboulle/clockwork from 0.4.0 to 0.5.0 by
@dependabot in #12430
- bump github.com/spf13/pflag from 1.0.5 to 1.0.6 by
@dependabot in #12548
- bump golang.org/x/sync from 0.10.0 to 0.11.0 by @dependabot
in #12547
- bump gotest.tools/v3 from 3.5.1 to 3.5.2 by @dependabot in
#12549
Update to version 2.32.4:
- add missing tag for build during merge workflow
- ci: re-use local source to build binary images
- ci: use local source for binary builds
Update to version 2.32.3:
- ci: update bake-action to v6
- simplification
- image can be set to a local ID, that isn't a valid docker ref
- can't render progress concurrently with buildkit
- exclude one-off container running convergence
- Only override service mac if set on the main network.
Update to version 2.32.2:
- remove engine v25 from e2e test matrix The 1st version
available for Ubuntu 24.x is Docker Engine v26
- fix relative path in compose file
- bump compose-go to v2.4.7
- replace tibdex/github-app-token by official GitHub
create-github-app-token
- bump golang.org/x/net to v0.33.0 to fix potential security
issue https://github.com/golang/go/issues/70906
- checkExpectedVolumes must ignore anonymous volumes
- When retrying to resolveOrCreateNetwork, retry with a valid
network name
- only check bind mount conflict if sync action is involved
- use the 3 latest major versions of the engine to run e2e step
- bump Golang version to v1.22.10 and update CI actions
- add --pull to run command
- CI to validate fmt
make fmtso any contributor can enforce formatting- format code with gofumpt
Update to version 2.32.1:
- e2e test to prevent future regression
- only check volume mounts for updated config
Update to ve
Affected software
SUSE-SU-2025:20385-1 is recorded against 1 package.
- docker-compose (fixed in 2.33.1-1.1)
Timeline and source
Published on 10 June 2025 and last revised on 23 March 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
www.suse.com (Advisory)
bugzilla.suse.com (Report)
www.suse.com (Web)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| docker-compose | — | 2.33.1-1.1 |
References
Similar Threats
- Unknown CGA-2mv5-7p9w-vp27
- Unknown CGA-24vx-jj57-3w5c
- Unknown CGA-234g-x4h3-6ppx
- Unknown AZL-76937
- Unknown AZL-76940
Free Vulnerability Check
Is your site affected by SUSE-SU-2025:20385-1?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2025:20385-1 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.