← Back

CVE-2019-5021

nvd nist
Published: May 8, 2019Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user. This vulnerability appears to be the result of a regression introduced in December of 2015. Due to the nature of this issue, systems deployed using affected versions of the Alpine Linux container which utilize Linux PAM, or some other mechanism which uses the system shadow file as an authentication database, may accept a NULL password for the `root` user.

Affected (4)

1 product
Docker Alpine
1 product
Leap
1 product
Big Ip Controller
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 3.3
Running on/withPlatform Versions
Alpinelinux
Alpine Linux
All versions
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Opensuse
Version 15.0
Version 15.1
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.2.1

References (12)

Source: talos-cna@cisco.com
Mailing ListThird Party Advisory
Source: talos-cna@cisco.com
Broken Link
Source: talos-cna@cisco.com
Third Party Advisory
Source: talos-cna@cisco.com
Third Party Advisory
Source: talos-cna@cisco.com
ExploitMitigationPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMitigationPatchThird Party Advisory

Timeline

No history available yet.