CVE-2020-29564: Critical severity hashicorp consul vulnerability
The official Consul Docker images 0.7.1 through 1.4.2 contain a blank password for a root user. System using the Consul Docker container deployed by affected versions of the Docker image may allow a remote attacker to achieve root access with a blank password.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-29564?
CVE-2020-29564 is considered a critical vulnerability due to the potential for remote attackers to achieve root access.
How do I fix CVE-2020-29564?
To fix CVE-2020-29564, update to a later version of the Consul Docker image that does not use a blank root password.
Which versions are affected by CVE-2020-29564?
CVE-2020-29564 affects Consul Docker images ranging from versions 0.7.1 to 1.4.2.
What impact does CVE-2020-29564 have on systems?
CVE-2020-29564 can allow remote attackers to gain unauthorized root access to systems using the affected Consul Docker images.
How can I determine if my system is vulnerable to CVE-2020-29564?
Check if you are running any version of the Consul Docker image between 0.7.1 and 1.4.2 to determine vulnerability to CVE-2020-29564.