{"id":33301,"date":"2019-10-31T21:51:51","date_gmt":"2019-10-31T18:51:51","guid":{"rendered":"https:\/\/prohoster.info\/blog\/docker-obrazy-alpine-postavlyalis-s-pustym-parolem-polzovatelya-root\/"},"modified":"2019-10-31T21:51:51","modified_gmt":"2019-10-31T18:51:51","slug":"docker-obrazy-alpine-postavlyalis-s-pustym-parolem-polzovatelya-root","status":"publish","type":"post","link":"https:\/\/prohoster.info\/fr\/blog\/news\/docker-obrazy-alpine-postavlyalis-s-pustym-parolem-polzovatelya-root","title":{"rendered":"Les images Docker Alpine \u00e9taient livr\u00e9es avec un mot de passe vide pour l'utilisateur root.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Des chercheurs en s\u00e9curit\u00e9 de Cisco <noindex><a rel=\"nofollow\" href=\"https:\/\/talosintelligence.com\/vulnerability_reports\/TALOS-2019-0782\">ont r\u00e9v\u00e9l\u00e9<\/a><\/noindex> informations sur la vuln\u00e9rabilit\u00e9 (CVE-2019-5021) dans <noindex><a rel=\"nofollow\" href=\"https:\/\/hub.docker.com\/_\/alpine\">les versions<\/a><\/noindex> la distribution Alpine pour le syst\u00e8me d'isolation de conteneurs Docker. La nature du probl\u00e8me identifi\u00e9 est que pour l'utilisateur root, un mot de passe vide a \u00e9t\u00e9 d\u00e9fini par d\u00e9faut sans blocage de l'acc\u00e8s direct en tant que root. Rappelons qu'Alpine est utilis\u00e9 pour cr\u00e9er des images officielles du projet Docker (auparavant, les constructions officielles \u00e9taient bas\u00e9es sur Ubuntu, mais ensuite elles ont \u00e9t\u00e9 <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=43828\">sont transf\u00e9r\u00e9es<\/a><\/noindex> sur Alpine).<\/p>\n<p>Le probl\u00e8me se manifeste depuis la version 3.3 d'Alpine Docker et a \u00e9t\u00e9 caus\u00e9 par un changement r\u00e9gressif introduit en 2015 (avant la version 3.3, la ligne &#171;root:!::0:::::&#187; \u00e9tait utilis\u00e9e dans \"\/etc\/shadow\", mais apr\u00e8s l'abandon du drapeau &#171;-d&#187;, la ligne &#171;root:::0:::::&#187; a commenc\u00e9 \u00e0 \u00eatre ajout\u00e9e). Le probl\u00e8me a \u00e9t\u00e9 initialement d\u00e9tect\u00e9 et <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/gliderlabs\/docker-alpine\/commit\/8b9abf92b9960b7153b93268580099f34ef20f69\">corrig\u00e9<\/a><\/noindex> en novembre 2015, mais en d\u00e9cembre, il a \u00e9t\u00e9 accidentellement r\u00e9introduit <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/gliderlabs\/docker-alpine\/commit\/ab4337c595383afa0f792ff01d3f99bc6667c3a8#diff-fc53135be554a2608c163978ed2f710b\">une grave<\/a><\/noindex> dans les fichiers d'assemblage de la branche exp\u00e9rimentale, puis a \u00e9t\u00e9 transf\u00e9r\u00e9 dans les versions stables.<\/p>\n<p>Les informations sur la vuln\u00e9rabilit\u00e9 indiquent que le probl\u00e8me appara\u00eet \u00e9galement dans la derni\u00e8re version Alpine Docker 3.9. Les d\u00e9veloppeurs d'Alpine en mars <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/docker-library\/official-images\/pull\/5516\">publi\u00e9s par<\/a><\/noindex> corrig\u00e9 et la vuln\u00e9rabilit\u00e9 <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/alpinelinux\/docker-alpine\/issues\/13\">n'appara\u00eet pas<\/a><\/noindex> \u00e0 partir des versions 3.9.2, 3.8.4, 3.7.3 et 3.6.5, mais reste dans les anciennes branches 3.4.x et 3.5.x, dont le support a d\u00e9j\u00e0 \u00e9t\u00e9 interrompu. De plus, les d\u00e9veloppeurs affirment que le vecteur d'attaque est fortement limit\u00e9 et n\u00e9cessite que l'attaquant ait acc\u00e8s \u00e0 la m\u00eame infrastructure.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source : <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50654\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Cisco \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0438 \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e\u0431 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2019-5021) \u0432 \u0441\u0431\u043e\u0440\u043a\u0430\u0445 \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u0430 Alpine \u0434\u043b\u044f \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u043a\u043e\u043d\u0442\u0435\u0439\u043d\u0435\u0440\u043d\u043e\u0439 \u0438\u0437\u043e\u043b\u044f\u0446\u0438\u0438 Docker. \u0421\u0443\u0442\u044c \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u043e\u0439 \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u044b \u0432 \u0442\u043e\u043c, \u0447\u0442\u043e \u0434\u043b\u044f \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f root \u0431\u044b\u043b \u0437\u0430\u0434\u0430\u043d \u043f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e \u043f\u0443\u0441\u0442\u043e\u0439 \u043f\u0430\u0440\u043e\u043b\u044c \u0431\u0435\u0437 \u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u043a\u0438 \u043f\u0440\u044f\u043c\u043e\u0433\u043e \u0432\u0445\u043e\u0434\u0430 \u043f\u043e\u0434 root. \u041d\u0430\u043f\u043e\u043c\u043d\u0438\u043c, \u0447\u0442\u043e Alpine \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f \u0434\u043b\u044f \u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u043e\u0444\u0438\u0446\u0438\u0430\u043b\u044c\u043d\u044b\u0445 \u043e\u0431\u0440\u0430\u0437\u043e\u0432 \u043e\u0442 \u043f\u0440\u043e\u0435\u043a\u0442\u0430 Docker (\u0440\u0430\u043d\u044c\u0448\u0435 \u043e\u0444\u0438\u0446\u0438\u0430\u043b\u044c\u043d\u044b\u0435 \u0441\u0431\u043e\u0440\u043a\u0438 \u043e\u0441\u043d\u043e\u0432\u044b\u0432\u0430\u043b\u0438\u0441\u044c [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-33301","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Cisco \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0438 \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e\u0431 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2019-5021) \u0432.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/fr\/blog\/news\/docker-obrazy-alpine-postavlyalis-s-pustym-parolem-polzovatelya-root\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"fr_FR\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47Docker-\u043e\u0431\u0440\u0430\u0437\u044b Alpine \u043f\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u043b\u0438\u0441\u044c \u0441 \u043f\u0443\u0441\u0442\u044b\u043c \u043f\u0430\u0440\u043e\u043b\u0435\u043c \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f root | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Cisco \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0438 \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e\u0431 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2019-5021) \u0432.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/fr\/blog\/news\/docker-obrazy-alpine-postavlyalis-s-pustym-parolem-polzovatelya-root\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T18:51:51+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T18:51:51+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Les images Docker Alpine \u00e9taient livr\u00e9es avec un mot de passe vide pour l'utilisateur root | ProHoster","description":"Les chercheurs en s\u00e9curit\u00e9 de Cisco ont r\u00e9v\u00e9l\u00e9 des informations sur la vuln\u00e9rabilit\u00e9 (CVE-2019-5021) dans.","canonical_url":"https:\/\/prohoster.info\/fr\/blog\/news\/docker-obrazy-alpine-postavlyalis-s-pustym-parolem-polzovatelya-root","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"fr_FR","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47Docker-\u043e\u0431\u0440\u0430\u0437\u044b Alpine \u043f\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u043b\u0438\u0441\u044c \u0441 \u043f\u0443\u0441\u0442\u044b\u043c \u043f\u0430\u0440\u043e\u043b\u0435\u043c \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f root | ProHoster","og:description":"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Cisco \u0440\u0430\u0441\u043a\u0440\u044b\u043b\u0438 \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e\u0431 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2019-5021) \u0432.","og:url":"https:\/\/prohoster.info\/fr\/blog\/news\/docker-obrazy-alpine-postavlyalis-s-pustym-parolem-polzovatelya-root","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T18:51:51+00:00","article:modified_time":"2019-10-31T18:51:51+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"33301","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-21 14:43:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 02:43:31","updated":"2026-01-21 14:43:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/33301","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/comments?post=33301"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/33301\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/media?parent=33301"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/categories?post=33301"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/tags?post=33301"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}