PT-2018-11289 · Docker · Docker Moby+1
Abergmann
·
Published
2018-09-10
·
Updated
2024-01-31
·
CVE-2018-12608
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Docker Moby versions prior to 17.06.0
Description
An issue was discovered where the Docker engine validated a client TLS certificate using both the configured client CA root certificate and all system roots on non-Windows systems. This allowed a client with any domain validated certificate signed by a system-trusted root CA to authenticate.
Recommendations
For versions prior to 17.06.0, update to version 17.06.0 or later to resolve the issue.
Fix
Improper Certificate Validation
Authentication Bypass Using an Alternate Path or Channel
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Docker
Docker Moby