Vulnerabilities > CVE-2020-29579 - Unspecified vulnerability in Express-Gateway Docker Image

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
express-gateway
critical

Summary

The official Express Gateway Docker images before 1.14.0 contain a blank password for a root user. Systems using the Express Gateway Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access.

Vulnerable Configurations

Part Description Count
Application
Express-Gateway
1