First published: Tue Dec 08 2020(Updated: )
The official irssi docker images before 1.1-alpine (Alpine specific) contain a blank password for a root user. System using the irssi docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access with a blank password.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
irssi docker image | <1.1-alpine |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-29602 is considered critical due to the potential for unauthorized remote root access.
To fix CVE-2020-29602, upgrade to the irssi docker image version 1.1-alpine or later.
CVE-2020-29602 affects systems using the irssi docker images before version 1.1-alpine.
CVE-2020-29602 poses a risk of remote attackers gaining root access due to the blank password for the root user.
The fix for CVE-2020-29602 is not reversible as it involves upgrading to a more secure version of the irssi docker image.