CVE-2020-35191
17.12.2020, 02:15
The official drupal docker images before 8.5.10-fpm-alpine (Alpine specific) contain a blank password for a root user. System using the drupal docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.Enginsight
Vendor | Product | Version |
---|---|---|
drupal | drupal_docker_images | 8.3.1-fpm-alpine ≤ 𝑥 ≤ 8.5.10-fpm-alpine |
drupal | drupal_docker_images | 8.3.0-fpm-alpine |
drupal | drupal_docker_images | 8.3.0-fpm-alpine:rc2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration