CVE-2020-35468 describes a critical vulnerability in the Appbase streams Docker image version 2.1.2, where the root user is configured with a blank password. This flaw allows a remote attacker to gain root access to affected systems without authentication, posing a severe risk to confidentiality, integrity, and availability. While the CVSS score is 9.8 (CRITICAL) and its FAUCET Risk Score is high at 81/100, there is currently no evidence of active exploitation, nor are public exploit modules like Metasploit or Nuclei available. Despite limited community discussion and media coverage, the ease of exploitation makes this a significant concern for deployments using the vulnerable image.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.1.2CPE matchmatch criteria | cpe:2.3:a:appbase:streams:2.1.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.