CVE Vulnerabilities

CVE-2020-29578

Published: Dec 08, 2020 | Modified: Dec 22, 2020
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The official piwik Docker images before fpm-alpine (Alpine specific) contain a blank password for a root user. Systems using the Piwik Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access.

Affected Software

Name Vendor Start Version End Version
Piwik_fpm-alpine_docker_image Matomo 3 (including) 3 (including)
Piwik_fpm-alpine_docker_image Matomo 3.5 (including) 3.5 (including)
Piwik_fpm-alpine_docker_image Matomo 3.5.1 (including) 3.5.1 (including)
Piwik_fpm-alpine_docker_image Matomo 3.6 (including) 3.6 (including)
Piwik_fpm-alpine_docker_image Matomo 3.6.0 (including) 3.6.0 (including)

References