CVE-2018-12608 PUBLISHED

An issue was discovered in Docker Moby before 17.06.0. The Docker engine validated a client TLS certificate using both the configured client CA root certificate and all system roots on non-Windows systems. This allowed a client with any domain validated certificate signed by a system-trusted root CA (as opposed to one signed by the configured CA root certificate) to authenticate.

EPSS 0.45% · 63.4th percentile

Risk Scores

EPSS Score
0.45%
63.4th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSdocker.io0, 1.13.1-0ubuntu6, 17.03.2-0ubuntu1
Ubuntu:16.04:LTSdocker.io1.10.3-0ubuntu5, 1.10.3-0ubuntu6, 1.11.2-0ubuntu5~16.04

Timeline

References

Open in Interactive Console →