PT-2018-11289 · Docker · Docker Moby+1

·

CVE-2018-12608

·

Published

2018-09-10

·

Updated

2024-01-31

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Docker Moby versions prior to 17.06.0
Description An issue was discovered where the Docker engine validated a client TLS certificate using both the configured client CA root certificate and all system roots on non-Windows systems. This allowed a client with any domain validated certificate signed by a system-trusted root CA to authenticate.
Recommendations For versions prior to 17.06.0, update to version 17.06.0 or later to resolve the issue.

Fix

Improper Certificate Validation

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-12608
GHSA-QRQR-3X5J-2XW9

Affected Products

Docker
Docker Moby