PT-2020-17207 · Docker · Docker Registry

Published

2020-11-12

·

Updated

2020-12-15

·

CVE-2020-29591

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Docker Registry versions through 2.7.0
Description The issue concerns a blank password for the root user in affected Docker Registry versions. This could allow a remote attacker to gain root access using the blank password.
Recommendations For versions through 2.7.0, update to a version that includes a fix for the blank root password issue to prevent unauthorized root access.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-29591

Affected Products

Docker Registry