Vulnerability Description
The official Express Gateway Docker images before 1.14.0 contain a blank password for a root user. Systems using the Express Gateway Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Express-Gateway | Express-Gateway Docker Image | < 1.14.0 |
References
- https://github.com/koharin/koharin2/blob/main/CVE-2020-29579Third Party Advisory
- https://github.com/koharin/koharin2/blob/main/CVE-2020-29579Third Party Advisory
FAQ
What is CVE-2020-29579?
CVE-2020-29579 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The official Express Gateway Docker images before 1.14.0 contain a blank password for a root user. Systems using the Express Gateway Docker container deployed by affected versions of the Docker image ...
How severe is CVE-2020-29579?
CVE-2020-29579 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-29579?
Check the references section above for vendor advisories and patch information. Affected products include: Express-Gateway Express-Gateway Docker Image.