CVE-2020-29389: Docker Crux Linux Docker Image

Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.

The official Crux Linux Docker images 3.0 through 3.4 contain a blank password for a root user. System using the Crux Linux Docker container deployed by affected versions of the Docker image may allow an attacker to achieve root access with a blank password.

Affected products

  • Docker Crux Linux Docker Image: from 3.0, up to and including 3.4

Published 2020-12-02. Last modified 2026-06-17.