The official plone Docker images before version of 4.3.18-alpine (Alpine specific) contain a blank password for a root user. System using the plone docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.
{
"cpe": "cpe:2.3:a:plone:plone:*:*:*:*:*:*:*:*",
"source": "CPE_RANGE",
"extracted_events": [
{
"introduced": "4.0.0-alpine"
},
{
"fixed": "4.3.18-alpine"
}
]
}