CVE-2020-35192
17.12.2020, 02:15
The official vault docker images before 0.11.6 contain a blank password for a root user. System using the vault docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.Enginsight
Vendor | Product | Version |
---|---|---|
hashicorp | vault | 0.6.0 ≤ 𝑥 < 0.11.6 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration