CVE-2020-35191: Critical severity drupal internationalization vulnerability
The official drupal docker images before 8.5.10-fpm-alpine (Alpine specific) contain a blank password for a root user. System using the drupal docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-35191?
CVE-2020-35191 is a vulnerability found in the official Drupal docker images before 8.5.10-fpm-alpine (Alpine specific) where the root user has a blank password.
How does CVE-2020-35191 impact systems?
CVE-2020-35191 allows a remote attacker to achieve root access on systems using the affected versions of the Drupal docker image with the blank password.
What is the severity of CVE-2020-35191?
CVE-2020-35191 has a severity score of 9.8, which is considered critical.
Which software versions are affected by CVE-2020-35191?
Versions before 8.5.10-fpm-alpine of the Drupal docker images (Alpine specific) are affected by CVE-2020-35191.
How do I fix CVE-2020-35191?
To fix CVE-2020-35191, update your Drupal docker images to version 8.5.10-fpm-alpine or later.