HIGH
Bullfrog's DNS over TCP bypasses domain filtering
Published May 14, 2025
8.6
HIGHCVSS 3.1
EPSS 0.47%
Description
Bullfrog is a GithHb Action to block unauthorized outbound traffic in GitHub workflows. Prior to version 0.8.4, using tcp breaks blocking and allows DNS exfiltration. This can result in sandbox bypass. Version 0.8.4 fixes the issue.
Affected products
-
Affected
- < 0.8.4
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Bullfrogsec | Bullfrog | unknown | Affected
|
- < 0.8.4
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-28122 Advisory
- https://github.com/advisories/GHSA-m32f-fjw2-37v3 Advisory
- https://github.com/bullfrogsec/bullfrog/commit/ae7744ae4b3a6f8ffc2e49f501e30bf1a43d4671 x_refsource_MISCPatch
- https://github.com/bullfrogsec/bullfrog/releases/tag/v0.8.4 x_refsource_MISCRelease Notes
- https://github.com/bullfrogsec/bullfrog/security/advisories/GHSA-m32f-fjw2-37v3 exploitx_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-47775
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-28122 | Advisory | |
| https://github.com/advisories/GHSA-m32f-fjw2-37v3 | Advisory | |
| https://github.com/bullfrogsec/bullfrog/commit/ae7744ae4b3a6f8ffc2e49f501e30bf1a43d4671 | x_refsource_MISCPatch | |
| https://github.com/bullfrogsec/bullfrog/releases/tag/v0.8.4 | x_refsource_MISCRelease Notes | |
| https://github.com/bullfrogsec/bullfrog/security/advisories/GHSA-m32f-fjw2-37v3 | exploitx_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2025-47775 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published May 14, 2025
Updated May 14, 2025
Reserved May 9, 2025
Link CVE-2025-47775
CISA Vulnrichment
Updated May 14, 2025
Red Hat
No data
GitHub
Link GHSA-M32F-FJW2-37V3