CVE-2020-35189: Critical severity kong kubernetes alpine docker image vulnerability
Published Dec 17, 2020
·Updated
The official kong docker images before 1.0.2-alpine (Alpine specific) contain a blank password for a root user. System using the kong docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.
Affected Software
1 affected component
kong Kong Alpine Docker Image<1.0.2
Event History
Dec 17, 2020
CVE Published
via MITRE·12:44 AM
Data Sourced
via MITRE·12:44 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-35189?
CVE-2020-35189 is considered a critical vulnerability due to the potential for remote attackers to gain root access.
2
How do I fix CVE-2020-35189?
To fix CVE-2020-35189, upgrade to Kong Docker image version 1.0.2 or later.
3
What kind of access can be gained through CVE-2020-35189?
CVE-2020-35189 allows remote attackers to achieve root access due to a blank password for the root user.
4
Which versions of Kong Docker images are affected by CVE-2020-35189?
Kong Docker images before version 1.0.2-alpine are affected by CVE-2020-35189.
5
Is the issue related to specific operating systems for CVE-2020-35189?
Yes, CVE-2020-35189 specifically relates to the Alpine variant of the Kong Docker image.