Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-5021

Опубликовано: 08 мая 2019
Источник: nvd
CVSS3: 9.8
CVSS3: 9.8
CVSS2: 10
EPSS Низкий

Описание

Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the root user. This vulnerability appears to be the result of a regression introduced in December of 2015. Due to the nature of this issue, systems deployed using affected versions of the Alpine Linux container which utilize Linux PAM, or some other mechanism which uses the system shadow file as an authentication database, may accept a NULL password for the root user.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:gliderlabs:docker-alpine:*:*:*:*:*:*:*:*
Версия от 3.3 (включая)
cpe:2.3:o:alpinelinux:alpine_linux:-:*:*:*:*:*:*:*
Конфигурация 2

Одно из

cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*
Конфигурация 3
cpe:2.3:a:f5:big-ip_controller:1.2.1:*:*:*:*:cloud_foundry:*:*

EPSS

Процентиль: 88%
0.0371
Низкий

9.8 Critical

CVSS3

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-258
NVD-CWE-Other

Связанные уязвимости

suse-cvrf
больше 6 лет назад

Recommended update for sles12sp3-docker-image, sles12sp4-image, system-user-root

suse-cvrf
около 4 лет назад

Security update for sles12sp2-docker-image

suse-cvrf
больше 6 лет назад

Recommended update for sles12sp3-docker-image, sles12sp4-image, system-user-root

suse-cvrf
больше 6 лет назад

Recommended update for sles12sp3-docker-image, sles12sp4-image, system-user-root

CVSS3: 9.8
github
больше 3 лет назад

Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user. This vulnerability appears to be the result of a regression introduced in December of 2015. Due to the nature of this issue, systems deployed using affected versions of the Alpine Linux container which utilize Linux PAM, or some other mechanism which uses the system shadow file as an authentication database, may accept a NULL password for the `root` user.

EPSS

Процентиль: 88%
0.0371
Низкий

9.8 Critical

CVSS3

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-258
NVD-CWE-Other