PT-2020-17332 · Blackfire · Blackfire Docker Image

Published

2020-12-15

·

Updated

2023-09-26

·

CVE-2020-35466

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Blackfire Docker image through 2020-12-14
Description The issue concerns a blank password for the root user in the Blackfire Docker image. This could allow a remote attacker to achieve root access with a blank password, potentially compromising systems deployed using affected versions of the Blackfire container.
Recommendations For Blackfire Docker image versions through 2020-12-14, update the root user password to a secure value to prevent unauthorized access. Consider restricting access to the container until the password can be updated.

Exploit

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2020-35466

Affected Products

Blackfire Docker Image