Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m3hq-qcc9-75f6

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the root user. This vulnerability appears to be the result of a regression introduced in December of 2015. Due to the nature of this issue, systems deployed using affected versions of the Alpine Linux container which utilize Linux PAM, or some other mechanism which uses the system shadow file as an authentication database, may accept a NULL password for the root user.

Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the root user. This vulnerability appears to be the result of a regression introduced in December of 2015. Due to the nature of this issue, systems deployed using affected versions of the Alpine Linux container which utilize Linux PAM, or some other mechanism which uses the system shadow file as an authentication database, may accept a NULL password for the root user.

EPSS

Процентиль: 88%
0.0371
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 9.8
nvd
больше 6 лет назад

Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user. This vulnerability appears to be the result of a regression introduced in December of 2015. Due to the nature of this issue, systems deployed using affected versions of the Alpine Linux container which utilize Linux PAM, or some other mechanism which uses the system shadow file as an authentication database, may accept a NULL password for the `root` user.

suse-cvrf
больше 6 лет назад

Recommended update for sles12sp3-docker-image, sles12sp4-image, system-user-root

suse-cvrf
около 4 лет назад

Security update for sles12sp2-docker-image

suse-cvrf
больше 6 лет назад

Recommended update for sles12sp3-docker-image, sles12sp4-image, system-user-root

suse-cvrf
больше 6 лет назад

Recommended update for sles12sp3-docker-image, sles12sp4-image, system-user-root

EPSS

Процентиль: 88%
0.0371
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-798