tmjpugh
(Tmjpugh)
1
Just in case some of you are using this
HA uses python base so no affect I think
https://talosintelligence.com/vulnerability_reports/TALOS-2019-0782
Hassio uses a Linux, I believe Alpine Linux, with Docker. Actually the report says it has NO root password.
hijinx
(James)
3
Just came to post the same news
tmjpugh
(Tmjpugh)
4
this is a problem with several Official docker images it seems.
Still, this is fairly local type exploit(physical access needed) unless paired with some other exploit correct? Although that’s not great either.
EDIT
I guess someone made a script to check this and there is a list
LIST
ARTICLE