The official drupal docker images before 8.5.10-fpm-alpine (Alpine specific) contain a blank password for a root user. System using the drupal docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.
2020-12-17T02:15:13.130
2024-11-21T05:26:55.607
Modified
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | drupal | drupal_docker_images | ≤ 8.5.10-fpm-alpine | Yes |
Application | drupal | drupal_docker_images | 8.3.0-fpm-alpine | Yes |
Application | drupal | drupal_docker_images | 8.3.0-fpm-alpine | Yes |