← Back to browse · API

CVE-2019-5021

Severity
CRITICAL
CVSS
9.8
EPSS
0.06263
Risk score
41.39
CISA KEV
No
PoC
No
Published
2019-05-08
Modified
2024-08-04
First seen
2026-08-07
Aliases
EUVD-2019-14628, GHSA-M3HQ-QCC9-75F6
Products
open source:Alpine Linux Alpine Docker 3.3 Alpine Docker 3.4 Alpine Docker 3.5 Alpine Docker 3.6 Alpine Docker 3.7 Alpine Docker 3.8 Alpine Docker 3.9 Alpine Docker Edge
Sources
euvd EUVD-2019-14628

Description

Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user. This vulnerability appears to be the result of a regression introduced in December of 2015. Due to the nature of this issue, systems deployed using affected versions of the Alpine Linux container which utilize Linux PAM, or some other mechanism which uses the system shadow file as an authentication database, may accept a NULL password for the `root` user.

References