Back
CVE-2019-5021
CRITICAL
Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user. This vulnerability appears to be the result of a regression introduced in December of 2015. Due to the nature of this issue, systems deployed using affected versions of the Alpine Linux container which utilize Linux PAM, or some other mechanism which uses the system shadow file as an authentication database, may accept a NULL password for the `root` user.
Published: May 8, 2019
Modified: Jun 17, 2026
CWE-258
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (4)
| Vendor | Product | Version |
|---|---|---|
| gliderlabs | docker-alpine | * ≥ 3.3 |
| opensuse | leap | 15.0 |
| opensuse | leap | 15.1 |
| f5 | big-ip_controller | 1.2.1 |
GitHub Security Advisory GHSA-m3hq-qcc9-75f6
Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the ...
References (12)
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00004.html Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/108288 Broken Link
- https://alpinelinux.org/posts/Docker-image-vulnerability-CVE-2019-5021.html Vendor Advisory
- https://security.netapp.com/advisory/ntap-20190510-0001/ Third Party Advisory
- https://support.f5.com/csp/article/K25551452 Third Party Advisory
- https://talosintelligence.com/vulnerability_reports/TALOS-2019-0782 Exploit, Mitigation, Patch, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00004.html Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/108288 Broken Link
- https://alpinelinux.org/posts/Docker-image-vulnerability-CVE-2019-5021.html Vendor Advisory
- https://security.netapp.com/advisory/ntap-20190510-0001/ Third Party Advisory
- https://support.f5.com/csp/article/K25551452 Third Party Advisory
- https://talosintelligence.com/vulnerability_reports/TALOS-2019-0782 Exploit, Mitigation, Patch, Third Party Advisory
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
6.26%
Top 7% most likely to be exploited
Threat Score
41.1 / 100
Data Sources
NVD
EPSS
GitHub