Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user. This vulnerability appears to be the result of a regression introduced in December of 2015. Due to the nature of this issue, systems deployed using affected versions of the Alpine Linux container which utilize Linux PAM, or some other mechanism which uses the system shadow file as an authentication database, may accept a NULL password for the `root` user.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAlpinelinux Alpine Linux
OSAlpinelinuxall versionsF5 Big Ip Controller
APPF51.2.1Gliderlabs Docker Alpine
APPGliderlabs≥ 3.3Opensuse Leap
OSOpensuse15.015.1
Related vulnerabilities
Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)
SaltStack Salt API — shell injection przez klienta SSH (RCE)
Command injection w Roundcube Webmail — RCE przez konfigurację ImageMagick
SaltStack Salt: nieautoryzowany dostęp do metod salt-master umożliwiający RCE
Apache Tomcat AJP Connector — odczyt plików i RCE (Ghostcat)