Review the container SSH port declaration

Declare only required service ports and separately restrict actual port publishing and SSH access.

Description

EXPOSE 22 in a Dockerfile is metadata indicating that the image uses that port. It does not start an SSH server or publish a host port. Automatic publishing such as -P can use EXPOSE metadata.

If an SSH service is actually running and externally reachable, review its authentication and access scope. Removing EXPOSE does not block explicit port mappings or other network paths.

Potential impact

  • An unnecessary port declaration combined with automatic publishing can create an unintended access path.
  • Weak authentication or vulnerable software on a reachable SSH service can allow container compromise.

Remediation

  • Remove unnecessary EXPOSE 22 declarations and review running services, actual port mappings and firewalls together.
  • Consider access-controlled command-execution and logging tools for administration. If SSH is required, limit it to trusted management paths and strong authentication.

Examples

The examples compare port declarations only. Adding EXPOSE 22 does not create an SSH server in the Nginx image.

Before

dockerfile
FROM nginx:1.27-alpine

EXPOSE 80 22
CMD ["nginx", "-g", "daemon off;"]

After

dockerfile
FROM nginx:1.27-alpine

EXPOSE 80
CMD ["nginx", "-g", "daemon off;"]

Explanation:

  • Before: Ports 80 and 22 are declared. Actual publishing and running services depend on separate configuration.
  • After: The declaration of port 22 is removed. This does not block explicit publishing or network access.

References