First published: Thu Dec 17 2020(Updated: )
The official adminer docker images before 4.7.0-fastcgi contain a blank password for a root user. System using the adminer docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Docker Adminer | >=4.2.5-fastcgi<4.7.0-fastcgi |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-35186 is a vulnerability found in the official adminer docker images before version 4.7.0-fastcgi.
CVE-2020-35186 has a severity rating of critical, with a score of 9.8.
CVE-2020-35186 affects systems that are using the adminer docker container deployed by affected versions of the docker image.
CVE-2020-35186 poses a risk of allowing a remote attacker to achieve root access with a blank password.
To fix CVE-2020-35186, update the adminer docker image to version 4.7.0-fastcgi or later.