The official eggdrop Docker images before 1.8.4rc2 contain a blank password for a root user. Systems using the Eggdrop Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access with a blank password.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Eggdrop_docker_image | Eggheads | 1.6 (including) | 1.6 (including) |
Eggdrop_docker_image | Eggheads | 1.6.21 (including) | 1.6.21 (including) |
Eggdrop_docker_image | Eggheads | 1.8.0 (including) | 1.8.0 (including) |
Eggdrop_docker_image | Eggheads | 1.8.0-rc1 (including) | 1.8.0-rc1 (including) |
Eggdrop_docker_image | Eggheads | 1.8.0-rc2 (including) | 1.8.0-rc2 (including) |
Eggdrop_docker_image | Eggheads | 1.8.0-rc3 (including) | 1.8.0-rc3 (including) |
Eggdrop_docker_image | Eggheads | 1.8.0-rc4 (including) | 1.8.0-rc4 (including) |
Eggdrop_docker_image | Eggheads | 1.8.1 (including) | 1.8.1 (including) |
Eggdrop_docker_image | Eggheads | 1.8.1-rc2 (including) | 1.8.1-rc2 (including) |
Eggdrop_docker_image | Eggheads | 1.8.2 (including) | 1.8.2 (including) |
Eggdrop_docker_image | Eggheads | 1.8.2-rc1 (including) | 1.8.2-rc1 (including) |
Eggdrop_docker_image | Eggheads | 1.8.2-rc2 (including) | 1.8.2-rc2 (including) |
Eggdrop_docker_image | Eggheads | 1.8.3 (including) | 1.8.3 (including) |
Eggdrop_docker_image | Eggheads | 1.8.3-rc1 (including) | 1.8.3-rc1 (including) |
Eggdrop_docker_image | Eggheads | 1.8.4 (including) | 1.8.4 (including) |
Eggdrop_docker_image | Eggheads | 1.8.4-rc1 (including) | 1.8.4-rc1 (including) |
Eggdrop_docker_image | Eggheads | 1.8.4-rc2 (including) | 1.8.4-rc2 (including) |
Eggdrop_docker_image | Eggheads | 1.8.4-rc3 (including) | 1.8.4-rc3 (including) |