Alpine Linux Docker images ship a root account with no password

General News

Summary

All Alpine Linux Docker images, since v3.3, are impacted, Cisco Talos said today in a security alert . The issue was first discovered back in August 2015, patched in November , then accidentally three weeks later, in December 2015, only to be re-discovered again by a Cisco Umbrella researcher in January this year. Servers and workstations that have been provisioned/installed from Glider Labs Alpine Linux Docker images are now at risk of being hijacked by attackers who can authenticate using the root user and no password. While new Alpine Linux images have been released on Docker Hub, existing systems should be modified to either disable the root account or, at least, set a custom password. "The likelihood of exploitation of this vulnerability is environment-dependent, as successful exploitation requires that an exposed service or application utilise Linux PAM [Pluggable Authentication Modules], or some other mechanism which uses the system shadow file as an authentication database," Cisco said today.

Classifications

industries
No industries detected
applications
EduTech - learning

AskAI Classifications

Labels
Developer Tools DevOps Software SaaS

Linked Companies

GitHub, Inc.
$1M to $5M