
Root user has no password

aronmolnar opened this issue · 1 comments

The root user in the docker image has no password.
This may make it possible - if the service (running as nobody) is compromized - that an attacker could become root.

It should be sufficient to pull the latest alpine image an rebuild the image.

See also:

Relates #23

I've pushed new releases that have this fixed at 2.79 and later.