CVE-2018-12608

HIGH

Docker Moby <17.06.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

An issue was discovered in Docker Moby before 17.06.0. The Docker engine validated a client TLS certificate using both the configured client CA root certificate and all system roots on non-Windows systems. This allowed a client with any domain validated certificate signed by a system-trusted root CA (as opposed to one signed by the configured CA root certificate) to authenticate.

References (1)

Core 1
Core References
Patch, Third Party Advisory x_refsource_misc
https://github.com/moby/moby/pull/33182

Scores

CVSS v3 7.5
EPSS 0.0092
EPSS Percentile 55.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-295
Status published
Products (2)
docker/docker 0 - 17.06.0-ceGo
mobyproject/moby < 17.06.0
Published Sep 10, 2018
Tracked Since Feb 18, 2026