{"id":"CVE-2020-29591","details":"Versions of the Official registry Docker images through 2.7.0 contain a blank password for the root user. Systems deployed using affected versions of the registry container may allow a remote attacker to achieve root access with a blank password.","modified":"2026-08-27T03:48:44.114007843Z","published":"2020-12-11T15:15:12.297Z","database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:a:docker:registry:2.5.0:rc2:*:*:*:*:*:*","cpe:2.3:a:docker:registry:2.5.0:rc:*:*:*:*:*:*","cpe:2.3:a:docker:registry:2.6.0:rc2:*:*:*:*:*:*","cpe:2.3:a:docker:registry:2.6.1:rc2:*:*:*:*:*:*"],"extracted_events":[{"introduced":"2.5.0-rc"},{"last_affected":"2.5.0-rc"},{"introduced":"2.5.0-rc2"},{"last_affected":"2.5.0-rc2"},{"introduced":"2.6.0-rc2"},{"last_affected":"2.6.0-rc2"},{"introduced":"2.6.1-rc2"},{"last_affected":"2.6.1-rc2"}],"source":"CPE_STRING","vendor_product":"docker:registry"}]},"references":[{"type":"WEB","url":"https://hub.docker.com/_/registry"},{"type":"ADVISORY","url":"https://github.com/donghyunlee00/CVE/blob/main/CVE-2020-29591"},{"type":"PACKAGE","url":"https://github.com/docker/distribution-library-image"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/distribution/distribution","events":[{"introduced":"a9b1322edf48b1fb9aee4e5ded7a4f4ac37c6830"},{"last_affected":"40b7b5830a2337bb07627617740c0e39eb92800c"}],"database_specific":{"source":"CPE_STRING","cpe":["cpe:2.3:a:docker:registry:2.5:*:*:*:*:*:*:*","cpe:2.3:a:docker:registry:2.5.0:*:*:*:*:*:*:*","cpe:2.3:a:docker:registry:2.5.1:*:*:*:*:*:*:*","cpe:2.3:a:docker:registry:2.6.0:*:*:*:*:*:*:*","cpe:2.3:a:docker:registry:2.6.1:*:*:*:*:*:*:*","cpe:2.3:a:docker:registry:2.7.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"2.5"},{"last_affected":"2.5"},{"introduced":"2.5.0"},{"last_affected":"2.5.0"},{"introduced":"2.5.1"},{"last_affected":"2.5.1"},{"introduced":"2.6.0"},{"last_affected":"2.6.0"},{"introduced":"2.6.1"},{"last_affected":"2.6.1"},{"introduced":"2.7.0"},{"last_affected":"2.7.0"}]}}],"versions":["2.5","2.5.1","2.6.0","2.6.1","2.7.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-29591.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}