Cockroach Labs cockroach-k8s-request-cert Empty Root Password Authentication Bypass Vulnerability. This vulnerability could allow remote attackers to bypass authentication on systems that use the affected version of the Cockroach Labs cockroach-k8s-request-cert container image.
The specific flaw exists within the configuration of the system shadow file. The issue results from a blank password setting for the root user. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-22195.
References
Link | Resource |
---|---|
https://www.zerodayinitiative.com/advisories/ZDI-25-855/ |
Configurations
No configuration.
History
02 Sep 2025, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-02 20:15
Updated : 2025-09-04 15:36
NVD link : CVE-2025-9276
Mitre link : CVE-2025-9276
CVE.ORG link : CVE-2025-9276
JSON object : View
Products Affected
No product.
CWE
CWE-258
Empty Password in Configuration File