CVSS v3
9.8
CRITICAL
EPSS Score
3.6 %
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
Description
Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user. This vulnerability appears to be the result of a regression introduced in December of 2015. Due to the nature of this issue, systems deployed using affected versions of the Alpine Linux container which utilize Linux PAM, or some other mechanism which uses the system shadow file as an authentication database, may accept a NULL password for the `root` user.
Technical details
- Published
- 2019-05-08
Frequently asked questions
What is CVE-2019-5021?
Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user. This vulnerability appears to be the result of a regression introduced in December of 2015. Due to the nature of this issue, systems deployed using affected versions of the Alpine Linux container which utilize Linux PAM, or some other mechanism which uses the system shadow file as an authentication database, may accept a NULL password for the `root` user.
Is CVE-2019-5021 actively exploited?
Active exploitation of CVE-2019-5021 has not been confirmed. The EPSS score is 3.6%, indicating the estimated probability of exploitation in the next 30 days.
What is the CVSS score for CVE-2019-5021?
CVE-2019-5021 has a CVSS v3 base score of 9.8 (CRITICAL severity).
Is CVE-2019-5021 affecting your environment?
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
No credit card required · 500 free checks/month · Free API key
Other 2019 vulnerabilities worth triaging
Ranked by exploit probability (EPSS).