First published: Tue Dec 08 2020(Updated: )
The official storm Docker images before 1.2.1 contain a blank password for a root user. Systems using the Storm Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access with a blank password.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Docker Storm Docker Image | <1.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-29580 is a vulnerability found in the official storm Docker images before version 1.2.1, where a blank password is used for the root user, potentially allowing remote attackers to gain root access.
CVE-2020-29580 has a severity rating of 9.8, which is classified as critical.
The Docker Storm Docker Image versions up to and excluding 1.2.1 are affected by CVE-2020-29580.
An attacker can exploit CVE-2020-29580 by gaining remote access to a system using the affected Docker Storm Docker Image and leveraging the blank password for the root user to achieve root access.
Yes, upgrading to version 1.2.1 or later of the official storm Docker images will fix the vulnerability.