CVE-2020-29591

Versions of the Official registry Docker images through 2.7.0 contain a blank password for the root user. Systems deployed using affected versions of the registry container may allow a remote attacker to achieve root access with a blank password.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 85%
VendorProductVersion
dockerregistry
2.5
dockerregistry
2.5.0
dockerregistry
2.5.0:rc
dockerregistry
2.5.0:rc2
dockerregistry
2.5.1
dockerregistry
2.6.0
dockerregistry
2.6.0:rc2
dockerregistry
2.6.1
dockerregistry
2.6.1:rc2
dockerregistry
2.7.0
𝑥
= Vulnerable software versions