CVE-2020-29578: Critical severity Matomo Piwik Fpm-alpine Docker Image vulnerability
Published Dec 8, 2020
·Updated
The official piwik Docker images before fpm-alpine (Alpine specific) contain a blank password for a root user. Systems using the Piwik Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access.
Affected Software
5 affected components
Matomo Piwik Fpm-alpine Docker Image=3
Matomo Piwik Fpm-alpine Docker Image=3.5
Matomo Piwik Fpm-alpine Docker Image=3.5.1
Matomo Piwik Fpm-alpine Docker Image=3.6
Matomo Piwik Fpm-alpine Docker Image=3.6.0
Event History
Dec 8, 2020
CVE Published
via MITRE·03:02 PM
Data Sourced
via MITRE·03:02 PM
Description
Data Sourced
03:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-29578?
CVE-2020-29578 has a high severity due to the potential for remote root access.
2
How do I fix CVE-2020-29578?
To fix CVE-2020-29578, update to a fixed version of the Piwik Docker image that does not have a blank root password.
3
Who is affected by CVE-2020-29578?
Users of the Piwik Docker images prior to fpm-alpine are affected by CVE-2020-29578.
4
What could happen if I am vulnerable to CVE-2020-29578?
If vulnerable to CVE-2020-29578, attackers could gain unauthorized root access to your system.
5
Is there a workaround for CVE-2020-29578 until I can update?
A potential workaround for CVE-2020-29578 is to change the root password of the container immediately.