CVE-2019-5021
Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user. This vulnerability appears to be the result of a regression introduced in December of 2015. Due to the nature of this issue, systems deployed using affected versions of the Alpine Linux container which utilize Linux PAM, or some other mechanism which uses the system shadow file as an authentication database, may accept a NULL password for the `root` user.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 3.64%
- CWE
- CWE-258
- Published
- 2019-05-08
- Last modified
- 2026-03-14
Affected products
- n/a Alpine Linux
Weakness type
Related vulnerabilities
- CVE-2025-9276 — Cockroach Labs cockroach-k8s-request-cert Empty Root Password Authentication Bypass Vulnerability
- CVE-2025-4395 — Medtronic MyCareLink Patient Monitor Empty Password Vulnerability
- CVE-2024-35137 — IBM Security Access Manager Docker information disclosure
- CVE-2024-4106 — A vulnerability has been found in FAST/TOOLS and CI Server. The affected products have built-in...
- CVE-2023-43016 — IBM Security Access Manager Container unauthorized access
- CVE-2023-39439 — SAP Commerce accepts empty passphrases.
- CVE-2020-29478 — CA Service Catalog 17.2 and 17.3 contain a vulnerability in the default configuration of the Setup...
- CVE-2018-17914 — InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine...