CVE-2019-5021
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user. This vulnerability appears to be the result of a regression introduced in December of 2015. Due to the nature of this issue, systems deployed using affected versions of the Alpine Linux container which utilize Linux PAM, or some other mechanism which uses the system shadow file as an authentication database, may accept a NULL password for the `root` user.
Algunas versiones de las imágenes de Official Alpine Linux Docker (desde v3.3) contienen una contraseña NULL para el usuario `root`. Esta vulnerabilidad parece ser el resultado de una regresión introducida en diciembre de 2015. Debido a la naturaleza de este problema, los sistemas implementados utilizando las versiones afectadas del contenedor de Alpine Linux que utilizan Linux PAM, o algún otro mecanismo que utiliza el archivo de sistema shadow como una base de datos de autenticación, puede aceptar una contraseña NULL para el usuario `root`.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-01-04 CVE Reserved
- 2019-05-08 CVE Published
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-258: Empty Password in Configuration File
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/108288 | Broken Link | |
https://security.netapp.com/advisory/ntap-20190510-0001 | Third Party Advisory |
|
https://support.f5.com/csp/article/K25551452 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://talosintelligence.com/vulnerability_reports/TALOS-2019-0782 | 2024-08-04 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Gliderlabs Search vendor "Gliderlabs" | Docker-alpine Search vendor "Gliderlabs" for product "Docker-alpine" | >= 3.3 Search vendor "Gliderlabs" for product "Docker-alpine" and version " >= 3.3" | - |
Affected
| in | Alpinelinux Search vendor "Alpinelinux" | Alpine Linux Search vendor "Alpinelinux" for product "Alpine Linux" | - | - |
Safe
|
Opensuse Search vendor "Opensuse" | Leap Search vendor "Opensuse" for product "Leap" | 15.0 Search vendor "Opensuse" for product "Leap" and version "15.0" | - |
Affected
| ||||||
Opensuse Search vendor "Opensuse" | Leap Search vendor "Opensuse" for product "Leap" | 15.1 Search vendor "Opensuse" for product "Leap" and version "15.1" | - |
Affected
| ||||||
F5 Search vendor "F5" | Big-ip Controller Search vendor "F5" for product "Big-ip Controller" | 1.2.1 Search vendor "F5" for product "Big-ip Controller" and version "1.2.1" | cloud_foundry |
Affected
|