← Back

CVE-2020-29591

nvd nist
Published: Dec 11, 2020Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Versions of the Official registry Docker images through 2.7.0 contain a blank password for the root user. Systems deployed using affected versions of the registry container may allow a remote attacker to achieve root access with a blank password.

Affected (10)

Products: Docker: Registry
1 product
Registry
Configuration A
10 vulnerable
Vulnerable SoftwareAffected Versions
Docker
Version 2.5.0
Version 2.5.0 rc2
Version 2.5.0 rc
Version 2.5.1
Version 2.5
Version 2.6.0
Version 2.6.0 rc2
Version 2.6.1
Version 2.6.1 rc2
Version 2.7.0

References (6)

Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Product
Source: af854a3a-2127-422b-91ae-364da2661108
Product
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Product

Timeline

No history available yet.