GHSA-qrqr-3x5j-2xw9
Dashboard / Vulnerabilities / GHSA-qrqr-3x5j-2xw9
Summary: Docker Authentication Bypass
Details: An issue was discovered in Docker Moby before 17.06.0. The Docker engine validated a client TLS certificate using both the configured client CA root certificate and all system roots on non-Windows systems. This allowed a client with any domain validated certificate signed by a system-trusted root CA (as opposed to one signed by the configured CA root certificate) to authenticate.
References: https://nvd.nist.gov/vuln/detail/CVE-2018-12608, https://github.com/moby/moby/issues/33173, https://github.com/moby/moby/pull/33182, https://github.com/moby/moby/commit/190c6e8cf8b893874a33d83f78307f1bed0bfbcd, https://github.com/moby/moby
Affected packages
Package
Name: github.com/docker/docker
Purl: pkg:golang/github.com/docker/docker
Affected ranges
Type: ECOSYSTEM
Events:
