CVE-2019-5021

CRITICAL

Alpine Linux Docker <v3.3 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user. This vulnerability appears to be the result of a regression introduced in December of 2015. Due to the nature of this issue, systems deployed using affected versions of the Alpine Linux container which utilize Linux PAM, or some other mechanism which uses the system shadow file as an authentication database, may accept a NULL password for the `root` user.

References (6)

Core 6
Core References
Broken Link vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/108288
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00004.html
Exploit, Mitigation, Patch, Third Party Advisory x_refsource_misc
https://talosintelligence.com/vulnerability_reports/TALOS-2019-0782
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20190510-0001/
Third Party Advisory x_refsource_confirm
https://support.f5.com/csp/article/K25551452

Scores

CVSS v3 9.8
EPSS 0.0351
EPSS Percentile 87.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-258
Status published
Products (4)
f5/big-ip_controller 1.2.1
gliderlabs/docker-alpine 3.3
opensuse/leap 15.0
opensuse/leap 15.1
Published May 08, 2019
Tracked Since Feb 18, 2026