Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2g89-jxmp-m4m9

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The official chronograf docker images before 1.7.7-alpine (Alpine specific) contain a blank password for a root user. System using the chronograf docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.

The official chronograf docker images before 1.7.7-alpine (Alpine specific) contain a blank password for a root user. System using the chronograf docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.

Дефекты

CWE-306

Связанные уязвимости

nvd
около 5 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-5021. Reason: This candidate is a reservation duplicate of CVE-2019-5021. Notes: All CVE users should reference CVE-2019-5021 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usag

Дефекты

CWE-306