Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in Docker Moby before 17.06.0. The Docker engine validated a client TLS certificate using both the configured client CA root certificate and all system roots on non-Windows systems. This allowed a client with any domain validated certificate signed by a system-trusted root CA (as opposed to one signed by the configured CA root certificate) to authenticate.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Docker Moby 安全漏洞
Vulnerability Description
Docker Moby是一款用于在容器中安装系统的框架。 Docker Moby 17.06.0之前版本中存在安全漏洞,该漏洞源于Docker引擎采用配置的客户端CA root证书和非Windows系统上的所有系统root证书来验证客户端TLS证书。攻击者可利用该漏洞通过身份验证。
CVSS Information
N/A
Vulnerability Type
N/A