Since December 2015, Alpine Linux Docker images have been shipped with hardcoded credentials, a NULL password for the root user. The issue was first reported in August 2015 and patched in November, evidently, it was re-introduced in December 2015. The bug received a CVSS score of 9.8, it affects Alpine Docker versions 3.3 to 3.9, including Alpine Docker Edge. The good news is that the root account should be explicitly disabled in Docker images that are based on the vulnerable versions.”]

