Version 1.3.0 of the Weave Cloud Agent Docker image contains a blank password for the root user. Systems deployed using affected versions of the Weave Cloud Agent container may allow a remote attacker to achieve root access with a blank password.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HWeave Cloud Agent
APPWeave1.3.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Container
CWE
Related vulnerabilities
CVE-2022-35975CRITICAL9.0PL ✓same vendor
RCE w GitOps Tools Extension dla VSCode poprzez złośliwy obiekt Flux
CVE-2022-31098CRITICAL9.0PL ✓same vendor
Weave GitOps: ujawnienie tokenów Kubernetes w logach poda
CVE-2024-25545HIGH7.8same vendor
An issue in Weave Weave Desktop v.7.78.10 allows a local attacker to execute arbitrary code via a crafted scri...
CVE-2023-34236HIGH8.5same vendor
Weave GitOps Terraform Controller (aka Weave TF-controller) is a controller for Flux to reconcile Terraform re...
CVE-2022-23509HIGH7.3same vendor
Weave GitOps is a simple open source developer platform for people who want cloud native applications, without...