CVE-2025-9276
EUVD-2025-2643602.09.2025, 20:15
Cockroach Labs cockroach-k8s-request-cert Empty Root Password Authentication Bypass Vulnerability. This vulnerability could allow remote attackers to bypass authentication on systems that use the affected version of the Cockroach Labs cockroach-k8s-request-cert container image. The specific flaw exists within the configuration of the system shadow file. The issue results from a blank password setting for the root user. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-22195.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| cockroachlabs | cockroach-k8s-request-cert | - |
𝑥
= Vulnerable software versions
Common Weakness Enumeration