CVE-2019-5021
Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user. This vulnerability appears to be the result of a regression introduced in December of 2015. Due to the nature of this issue, systems deployed using affected versions of the Alpine Linux container which utilize Linux PAM, or some other mechanism which uses the system shadow file as an authentication database, may accept a NULL password for the `root` user.
Published:May 8, 2019
Last Modified:Nov 21, 2024
EPS:May 8, 2019
EPSS Score:0.0371
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Alpinelinux
Product
Alpine Linux
Alpinelinux
Alpine Linux
Vendor
F5
Product
Big-ip Controller
F5
Big-ip Controller
Vendor
Gliderlabs
Product
Docker-alpine
Gliderlabs
Docker-alpine
Vendor
Opensuse
Product
Leap
Opensuse
Leap
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
