Blank Password Vulnerability in Adminer Docker Images by Adminer
CVE-2020-35186

9.8CRITICAL

Key Information:

Vendor

Docker

Status
Vendor
CVE Published:
17 December 2020

What is CVE-2020-35186?

The Adminer Docker images prior to version 4.7.0-fastcgi have been identified to contain a configuration flaw that leaves the root user account without a password. This misconfiguration can be exploited by remote attackers, enabling unauthorized root access to systems running the affected Docker container. It is crucial for administrators to upgrade their images to the latest secured version to mitigate the risk of unauthorized access.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.