Back

HIGH

moby: cert signing bypass

Published Sep 10, 2018

Description

An issue was discovered in Docker Moby before 17.06.0. The Docker engine validated a client TLS certificate using both the configured client CA root certificate and all system roots on non-Windows systems. This allowed a client with any domain validated certificate signed by a system-trusted root CA (as opposed to one signed by the configured CA root certificate) to authenticate.

Affected products

Remediation

Red Hat mitigation

Some environments may be able to mitigate this issue by removing extra CAs from the host.

Metrics

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 10, 2018
Updated Aug 5, 2024
Reserved Jun 21, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Oct 9, 2018
GHSA-QRQR-3X5J-2XW9