CVE Vulnerabilities

CVE-2020-29578

Published: Dec 08, 2020 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The official piwik Docker images before fpm-alpine (Alpine specific) contain a blank password for a root user. Systems using the Piwik Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access.

Affected Software

Name Vendor Start Version End Version
Piwik_fpm-alpine_docker_image Matomo 3 (including) 3 (including)
Piwik_fpm-alpine_docker_image Matomo 3.5 (including) 3.5 (including)
Piwik_fpm-alpine_docker_image Matomo 3.5.1 (including) 3.5.1 (including)
Piwik_fpm-alpine_docker_image Matomo 3.6 (including) 3.6 (including)
Piwik_fpm-alpine_docker_image Matomo 3.6.0 (including) 3.6.0 (including)

References