CVE-2020-29578
08.12.2020, 15:15
The official piwik Docker images before fpm-alpine (Alpine specific) contain a blank password for a root user. Systems using the Piwik Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access.Enginsight
Vendor | Product | Version |
---|---|---|
matomo | piwik_fpm-alpine_docker_image | 3.5 |
matomo | piwik_fpm-alpine_docker_image | 3.5.1 |
matomo | piwik_fpm-alpine_docker_image | 3.6 |
matomo | piwik_fpm-alpine_docker_image | 3.6.0 |
𝑥
= Vulnerable software versions