Critical severity9.8NVD Advisory· Published Dec 8, 2020· Updated Jun 17, 2026
CVE-2020-29578
CVE-2020-29578
Description
The official piwik Docker images before fpm-alpine (Alpine specific) contain a blank password for a root user. Systems using the Piwik Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7cpe:2.3:a:matomo:piwik_fpm-alpine_docker_image:3.5.1:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:matomo:piwik_fpm-alpine_docker_image:3.5.1:*:*:*:*:*:*:*
- cpe:2.3:a:matomo:piwik_fpm-alpine_docker_image:3.5:*:*:*:*:*:*:*
- cpe:2.3:a:matomo:piwik_fpm-alpine_docker_image:3.6.0:*:*:*:*:*:*:*
- cpe:2.3:a:matomo:piwik_fpm-alpine_docker_image:3.6:*:*:*:*:*:*:*
- cpe:2.3:a:matomo:piwik_fpm-alpine_docker_image:3:*:*:*:*:*:*:*
- piwik/piwik Docker imagesdescription
Patches
Vulnerability mechanics
References
1- github.com/koharin/koharin2/blob/main/CVE-2020-29578nvdThird Party Advisory
News mentions
0No linked articles in our index yet.