First published: Thu Dec 17 2020(Updated: )
The official kong docker images before 1.0.2-alpine (Alpine specific) contain a blank password for a root user. System using the kong docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Kong Kubernetes Alpine Docker Image | <1.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-35189 is considered a critical vulnerability due to the potential for remote attackers to gain root access.
To fix CVE-2020-35189, upgrade to Kong Docker image version 1.0.2 or later.
CVE-2020-35189 allows remote attackers to achieve root access due to a blank password for the root user.
Kong Docker images before version 1.0.2-alpine are affected by CVE-2020-35189.
Yes, CVE-2020-35189 specifically relates to the Alpine variant of the Kong Docker image.