First published: Tue Dec 08 2020(Updated: )
The official elixir Docker images before 1.8.0-alpine (Alpine specific) contain a blank password for a root user. Systems using the elixir Linux Docker container deployed by affected versions of the Docker image may allow a remote attacker to achieve root access with a blank password.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Docker Elixir Alpine Docker Image | <1.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-29575 is considered a high severity vulnerability due to the risk of remote root access.
To fix CVE-2020-29575, update the Elixir Docker image to version 1.8.0-alpine or later.
CVE-2020-29575 affects all official Elixir Docker images before version 1.8.0-alpine.
The implications of CVE-2020-29575 include unauthorized root access, leading to potential system compromise.
You can verify if your system is vulnerable to CVE-2020-29575 by checking the version of the Elixir Docker image in use.