10
CVSSv2

CVE-2020-29578

Published: 08/12/2020 Updated: 22/12/2020
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The official piwik Docker images before fpm-alpine (Alpine specific) contain a blank password for a root user. Systems using the Piwik Docker container deployed by affected versions of the Docker image may allow an remote malicious user to achieve root access.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

matomo piwik fpm-alpine docker image 3

matomo piwik fpm-alpine docker image 3.5

matomo piwik fpm-alpine docker image 3.5.1

matomo piwik fpm-alpine docker image 3.6

matomo piwik fpm-alpine docker image 3.6.0