First published: Thu Dec 17 2020(Updated: )
The official drupal docker images before 8.5.10-fpm-alpine (Alpine specific) contain a blank password for a root user. System using the drupal docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
>=8.3.1-fpm-alpine<=8.5.10-fpm-alpine | ||
=8.3.0-fpm-alpine | ||
=8.3.0-fpm-alpine-rc2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-35191 is a vulnerability found in the official Drupal docker images before 8.5.10-fpm-alpine (Alpine specific) where the root user has a blank password.
CVE-2020-35191 allows a remote attacker to achieve root access on systems using the affected versions of the Drupal docker image with the blank password.
CVE-2020-35191 has a severity score of 9.8, which is considered critical.
Versions before 8.5.10-fpm-alpine of the Drupal docker images (Alpine specific) are affected by CVE-2020-35191.
To fix CVE-2020-35191, update your Drupal docker images to version 8.5.10-fpm-alpine or later.