CVE-2020-35193
16.12.2020, 00:15
The official sonarqube docker images before alpine (Alpine specific) contain a blank password for a root user. System using the sonarqube docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.Enginsight
Vendor | Product | Version |
---|---|---|
sonarsource | sonarqube_docker_image | 4.5.7 |
sonarsource | sonarqube_docker_image | 5.5 |
sonarsource | sonarqube_docker_image | 5.6 |
sonarsource | sonarqube_docker_image | 5.6.1 |
sonarsource | sonarqube_docker_image | 5.6.2 |
sonarsource | sonarqube_docker_image | 5.6.3 |
sonarsource | sonarqube_docker_image | 5.6.4 |
sonarsource | sonarqube_docker_image | 5.6.5 |
sonarsource | sonarqube_docker_image | 5.6.7 |
sonarsource | sonarqube_docker_image | 6.0 |
sonarsource | sonarqube_docker_image | 6.1 |
sonarsource | sonarqube_docker_image | 6.2 |
sonarsource | sonarqube_docker_image | 6.3 |
sonarsource | sonarqube_docker_image | 6.3.1 |
sonarsource | sonarqube_docker_image | 6.4 |
sonarsource | sonarqube_docker_image | 6.5 |
sonarsource | sonarqube_docker_image | 6.6 |
sonarsource | sonarqube_docker_image | 6.7 |
sonarsource | sonarqube_docker_image | 6.7.1 |
sonarsource | sonarqube_docker_image | 6.7.2 |
sonarsource | sonarqube_docker_image | 6.7.3 |
sonarsource | sonarqube_docker_image | 6.7.4 |
sonarsource | sonarqube_docker_image | 6.7.5 |
sonarsource | sonarqube_docker_image | 7.0 |
sonarsource | sonarqube_docker_image | 7.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration