Vulnerability Name:

CVE-2019-5021 (CCN-160705)

Assigned:2019-05-08
Published:2019-05-08
Updated:2022-06-13
Summary:Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user. This vulnerability appears to be the result of a regression introduced in December of 2015. Due to the nature of this issue, systems deployed using affected versions of the Alpine Linux container which utilize Linux PAM, or some other mechanism which uses the system shadow file as an authentication database, may accept a NULL password for the `root` user.
CVSS v3 Severity:9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
8.6 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
9.8 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
8.6 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
10.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2019-5021

Source: SUSE
Type: Mailing List, Third Party Advisory
openSUSE-SU-2019:1495

Source: BID
Type: Broken Link
108288

Source: MISC
Type: Vendor Advisory
https://alpinelinux.org/posts/Docker-image-vulnerability-CVE-2019-5021.html

Source: XF
Type: UNKNOWN
docker-cve20195021-unauth-access(160705)

Source: CCN
Type: Docker Web site
Alpine Linux

Source: CONFIRM
Type: Third Party Advisory
https://security.netapp.com/advisory/ntap-20190510-0001/

Source: CONFIRM
Type: Third Party Advisory
https://support.f5.com/csp/article/K25551452

Source: MISC
Type: Mitigation, Exploit, Third Party Advisory, Patch
https://talosintelligence.com/vulnerability_reports/TALOS-2019-0782

Source: CCN
Type: Talos Vulnerability Report TALOS-2019-0782
Alpine Linux Docker Image root User Hard-Coded Credential Vulnerability

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2019-5021

Vulnerable Configuration:Configuration 1:
  • cpe:/a:gliderlabs:docker-alpine:*:*:*:*:*:*:*:* (Version >= 3.3
  • AND
  • cpe:/o:alpinelinux:alpine_linux:-:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:opensuse:leap:15.0:*:*:*:*:*:*:*
  • OR cpe:/o:opensuse:leap:15.1:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/a:f5:big-ip_controller:1.2.1:*:*:*:*:cloud_foundry:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20195021
    V
    CVE-2019-5021
    2022-08-07
    oval:org.opensuse.security:def:1527
    P
    Security update for containerd, docker and runc (Important) (in QA)
    2022-06-14
    oval:org.opensuse.security:def:1317
    P
    Security update for the Linux Kernel (Live Patch 5 for SLE 15 SP3) (Important)
    2022-04-24
    oval:org.opensuse.security:def:20654
    P
    Security update for sles12sp2-docker-image (Important)
    2021-12-13
    oval:org.opensuse.security:def:49125
    P
    Security update for sles12sp2-docker-image (Important)
    2021-12-13
    oval:org.opensuse.security:def:64815
    P
    Security update for python-Babel (Important)
    2021-12-06
    oval:org.opensuse.security:def:68062
    P
    Security update for the Linux Kernel (Live Patch 24 for SLE 15 SP1) (Important)
    2021-10-12
    oval:org.opensuse.security:def:71402
    P
    syslog-service-2.0-2.23 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:48180
    P
    libpython2_7-1_0-2.7.13-28.31.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48044
    P
    ibus-1.5.13-15.11.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48163
    P
    libopenvswitch-2_11-0-2.11.1-1.75 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14074
    P
    DirectFB-1.7.1-6.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:13761
    P
    DirectFB-1.7.1-6.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48045
    P
    ibus-chewing-1.4.14-4.11 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14005
    P
    perl-LWP-Protocol-https-6.04-5.4 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47849
    P
    perl-Config-IniFiles-2.82-3.12 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:13893
    P
    libdcerpc-binding0-32bit-4.4.2-29.4 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14758
    P
    rrdtool-1.4.7-20.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48295
    P
    rpm-32bit-4.11.2-16.21.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14085
    P
    apache2-mod_jk-1.2.40-5.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:13829
    P
    giflib-progs-5.0.5-12.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48059
    P
    krb5-1.12.5-40.37.7 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14030
    P
    ruby-2.1-1.4 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14736
    P
    pigz-2.3-5.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47970
    P
    chrony-2.3-5.6.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47834
    P
    openslp-2.0.0-18.17.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:13912
    P
    libipa_hbac0-1.13.4-18.10 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47835
    P
    openssh-7.2p2-74.25.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14098
    P
    bzip2-1.0.6-29.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:13876
    P
    libXp6-1.0.2-3.57 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:63122
    P
    aws-cli-1.18.117-8.11.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63348
    P
    libshibsp-lite8-3.1.0-1.30 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:62782
    P
    libexempi-devel-2.4.5-3.3.2 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62303
    P
    python3-ecdsa-0.13.3-3.7.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62302
    P
    python3-cryptography-2.8-3.6.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62326
    P
    skopeo-0.1.41-4.11.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1955
    P
    subversion-bash-completion-1.10.6-3.15.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:64728
    P
    Security update for bluez (Moderate)
    2021-07-12
    oval:org.opensuse.security:def:38072
    P
    Security update for apache2 (Important)
    2021-06-17
    oval:org.opensuse.security:def:48959
    P
    openconnect-7.08-1.27 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48833
    P
    gcc48-gij-32bit-4.8.5-30.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48597
    P
    perl-LWP-Protocol-https-6.04-5.4 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48895
    P
    bogofilter-1.2.4-5.3 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48535
    P
    libpng15-15-1.5.22-4.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48373
    P
    augeas-1.2.0-10.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48745
    P
    libsilc-1_1-2-1.1.10-24.128 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:13731
    P
    sysconfig-0.83.8-7.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48960
    P
    pidgin-plugin-otr-4.0.2-1.29 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:13739
    P
    tomcat-8.0.23-1.80 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48749
    P
    libvdpau1-32bit-0.8-3.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48505
    P
    libimobiledevice6-1.2.0-7.31 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48387
    P
    coreutils-8.25-12.8 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:68162
    P
    Security update for the Linux Kernel (Live Patch 4 for SLE 15 SP2) (Important)
    2021-04-28
    oval:org.opensuse.security:def:48991
    P
    gnome-shell-calendar-3.20.4-77.23.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:71515
    P
    kernel-default-5.3.18-22.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2165
    P
    apache2-mod_security2-2.9.2-1.34 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:49043
    P
    libwpd-0_10-10-0.10.2-2.7.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62984
    P
    subversion-bash-completion-1.10.6-3.6.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62503
    P
    PackageKit-1.1.10-10.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:38487
    P
    squidGuard on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50392
    P
    Recommended update for sles12sp3-docker-image, sles12sp4-image, system-user-root (Important)
    2020-12-01
    oval:org.opensuse.security:def:37750
    P
    clamav on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50548
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:38219
    P
    hyper-v on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:74111
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:38598
    P
    gdk-pixbuf-lang on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64059
    P
    Security update for webkit2gtk3 (Important)
    2020-12-01
    oval:org.opensuse.security:def:50602
    P
    Recommended update for sles12sp3-docker-image, sles12sp4-image, system-user-root (Important)
    2020-12-01
    oval:org.opensuse.security:def:63809
    P
    Security update for accountsservice (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49201
    P
    libnewt0_52 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38526
    P
    xrdp on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37834
    P
    krb5 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38379
    P
    libtag1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:39236
    P
    typelib-1_0-Gtk-2_0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37738
    P
    automake on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49062
    P
    bzip2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49105
    P
    glibc-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37739
    P
    avahi on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38129
    P
    apache2-mod_perl on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64171
    P
    Security update for u-boot (Important)
    2020-12-01
    oval:org.opensuse.security:def:63915
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:39278
    P
    Recommended update for sles12sp3-docker-image, sles12sp4-image, system-user-root (Important)
    2020-12-01
    oval:org.opensuse.security:def:50338
    P
    Security update for libepubgen, liblangtag, libmwaw, libnumbertext, libreoffice, libstaroffice, libwps, myspell-dictionaries, xmlsec1 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49272
    P
    libzzip-0-13 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38554
    P
    bind on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37971
    P
    libtcnative-1-0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64017
    P
    Security update for apache2-mod_auth_openidc (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38438
    P
    perl-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:74237
    P
    Recommended update for sles12sp3-docker-image, sles12sp4-image, system-user-root (Important)
    2020-12-01
    oval:org.opensuse.security:def:63675
    P
    Security update for mariadb (Important)
    2020-12-01
    oval:org.opensuse.security:def:49170
    P
    libgstphotography-1_0-0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:90141
    P
    Recommended update for sles12sp3-docker-image, sles12sp4-image, system-user-root (Important)
    2019-10-11
    oval:org.opensuse.security:def:103796
    P
    Recommended update for sles12sp3-docker-image, sles12sp4-image, system-user-root (Important)
    2019-10-11
    oval:org.opensuse.security:def:109861
    P
    Recommended update for sles12sp3-docker-image, sles12sp4-image, system-user-root (Important)
    2019-06-03
    BACK
    gliderlabs docker-alpine *
    alpinelinux alpine linux -
    opensuse leap 15.0
    opensuse leap 15.1
    f5 big-ip controller 1.2.1