Description
EXPOSE 22 in a Dockerfile is metadata indicating that the image uses that port. It does not start an SSH server or publish a host port. Automatic publishing such as -P can use EXPOSE metadata.
If an SSH service is actually running and externally reachable, review its authentication and access scope. Removing EXPOSE does not block explicit port mappings or other network paths.
Potential impact
- An unnecessary port declaration combined with automatic publishing can create an unintended access path.
- Weak authentication or vulnerable software on a reachable SSH service can allow container compromise.
Remediation
- Remove unnecessary EXPOSE 22 declarations and review running services, actual port mappings and firewalls together.
- Consider access-controlled command-execution and logging tools for administration. If SSH is required, limit it to trusted management paths and strong authentication.
Examples
The examples compare port declarations only. Adding EXPOSE 22 does not create an SSH server in the Nginx image.
Before
dockerfile
FROM nginx:1.27-alpine
EXPOSE 80 22
CMD ["nginx", "-g", "daemon off;"]
After
dockerfile
FROM nginx:1.27-alpine
EXPOSE 80
CMD ["nginx", "-g", "daemon off;"]
Explanation:
- Before: Ports 80 and 22 are declared. Actual publishing and running services depend on separate configuration.
- After: The declaration of port 22 is removed. This does not block explicit publishing or network access.