CVE-2020-29580: Critical severity docker storm docker image vulnerability
The official storm Docker images before 1.2.1 contain a blank password for a root user. Systems using the Storm Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access with a blank password.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-29580?
CVE-2020-29580 is a vulnerability found in the official storm Docker images before version 1.2.1, where a blank password is used for the root user, potentially allowing remote attackers to gain root access.
How severe is CVE-2020-29580?
CVE-2020-29580 has a severity rating of 9.8, which is classified as critical.
What software is affected by CVE-2020-29580?
The Docker Storm Docker Image versions up to and excluding 1.2.1 are affected by CVE-2020-29580.
How can an attacker exploit CVE-2020-29580?
An attacker can exploit CVE-2020-29580 by gaining remote access to a system using the affected Docker Storm Docker Image and leveraging the blank password for the root user to achieve root access.
Is there a fix for CVE-2020-29580?
Yes, upgrading to version 1.2.1 or later of the official storm Docker images will fix the vulnerability.