CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2019-5021

CVSS 9.8v3.1pub. 2019-05-08upd. 2024-11-21

Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user. This vulnerability appears to be the result of a regression introduced in December of 2015. Due to the nature of this issue, systems deployed using affected versions of the Alpine Linux container which utilize Linux PAM, or some other mechanism which uses the system shadow file as an authentication database, may accept a NULL password for the `root` user.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Alpinelinux Alpine Linux

    OS
    Alpinelinux
    all versions
  • F5 Big Ip Controller

    APP
    F5
    1.2.1
  • Gliderlabs Docker Alpine

    APP
    Gliderlabs
    ≥ 3.3
  • Opensuse Leap

    OS
    Opensuse
    15.015.1
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Container
CWE
References

Related vulnerabilities

CVE-2025-32463CRITICAL9.3⚠ KEVPL ✓same product

Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)

CVE-2020-16846CRITICAL9.8⚠ KEVPL ✓same product

SaltStack Salt API — shell injection przez klienta SSH (RCE)

CVE-2020-12641CRITICAL9.8⚠ KEVPL ✓same product

Command injection w Roundcube Webmail — RCE przez konfigurację ImageMagick

CVE-2020-11651CRITICAL9.8⚠ KEVPL ✓same product

SaltStack Salt: nieautoryzowany dostęp do metod salt-master umożliwiający RCE

CVE-2020-1938CRITICAL9.8⚠ KEVPL ✓same product

Apache Tomcat AJP Connector — odczyt plików i RCE (Ghostcat)