PT-2018-11289 · Docker · Docker Moby+1

Abergmann

·

Publicado

2018-09-10

·

Atualizado

2024-01-31

·

CVE-2018-12608

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Docker Moby versions prior to 17.06.0
Description An issue was discovered where the Docker engine validated a client TLS certificate using both the configured client CA root certificate and all system roots on non-Windows systems. This allowed a client with any domain validated certificate signed by a system-trusted root CA to authenticate.
Recommendations For versions prior to 17.06.0, update to version 17.06.0 or later to resolve the issue.

Correção

Improper Certificate Validation

Authentication Bypass Using an Alternate Path or Channel

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-12608
GHSA-QRQR-3X5J-2XW9

Produtos afetados

Docker
Docker Moby