CVE Vulnerabilities

CVE-2020-29578

Published: Dec 08, 2020 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The official piwik Docker images before fpm-alpine (Alpine specific) contain a blank password for a root user. Systems using the Piwik Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access.

Affected Software

NameVendorStart VersionEnd Version
Piwik_fpm-alpine_docker_imageMatomo3 (including)3 (including)
Piwik_fpm-alpine_docker_imageMatomo3.5 (including)3.5 (including)
Piwik_fpm-alpine_docker_imageMatomo3.5.1 (including)3.5.1 (including)
Piwik_fpm-alpine_docker_imageMatomo3.6 (including)3.6 (including)
Piwik_fpm-alpine_docker_imageMatomo3.6.0 (including)3.6.0 (including)

References