PT-2018-11289 · Docker · Docker Moby+1
Abergmann
·
Publicado
2018-09-10
·
Atualizado
2024-01-31
·
CVE-2018-12608
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Docker Moby versions prior to 17.06.0
Description
An issue was discovered where the Docker engine validated a client TLS certificate using both the configured client CA root certificate and all system roots on non-Windows systems. This allowed a client with any domain validated certificate signed by a system-trusted root CA to authenticate.
Recommendations
For versions prior to 17.06.0, update to version 17.06.0 or later to resolve the issue.
Correção
Improper Certificate Validation
Authentication Bypass Using an Alternate Path or Channel
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Docker
Docker Moby