First published: Tue Dec 08 2020(Updated: )
The official notary docker images before signer-0.6.1-1 contain a blank password for a root user. System using the notary docker container deployed by affected versions of the docker image may allow an remote attacker to achieve root access with a blank password.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Docker Notary Docker Image | <signer-0.6.1-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-29601.
The severity of CVE-2020-29601 is critical with a CVSS score of 9.8.
The affected software of CVE-2020-29601 is the notary docker image before signer-0.6.1-1.
This vulnerability could allow a remote attacker to achieve root access with a blank password.
Yes, updating to signer-0.6.1-1 or later can address this vulnerability.