Alpine Docker Image ‘null root password’ Vulnerability
ID: 583e63e8-19d0-53e3-9231-d75db043417e
STIX ID: report--583e63e8-19d0-53e3-9231-d75db043417e
Feed Name: Aqua Security Blog
A vulnerability (CVE-2019-5021) in Alpine Linux Docker images sets the root account password to NULL by default for affected image releases, which can allow a non-root user to gain root inside the container if applications use Linux PAM or the /etc/shadow file for authentication. The advisory explains how to detect vulnerable images, lists fixed image releases, notes that older EOL versions remain vulnerable, and recommends updating to patched images or using image assurance checks to prevent deployment of vulnerable images.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
