PT-2018-11289 · Docker · Docker Moby+1

Abergmann

·

Published

2018-09-10

·

Updated

2024-01-31

·

CVE-2018-12608

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Docker Moby versions prior to 17.06.0
Description An issue was discovered where the Docker engine validated a client TLS certificate using both the configured client CA root certificate and all system roots on non-Windows systems. This allowed a client with any domain validated certificate signed by a system-trusted root CA to authenticate.
Recommendations For versions prior to 17.06.0, update to version 17.06.0 or later to resolve the issue.

Fix

Improper Certificate Validation

Authentication Bypass Using an Alternate Path or Channel

Weakness Enumeration

Related Identifiers

CVE-2018-12608
GHSA-QRQR-3X5J-2XW9

Affected Products

Docker
Docker Moby