CVE-2024-8287
Severity CVSS v4.0:
Pending analysis
Type:
CWE-295
Improper Certificate Validation
Publication date:
18/09/2024
Last modified:
24/09/2024
Description
Anbox Management Service, in versions 1.17.0 through 1.23.0, does not validate the TLS certificate provided to it by the Anbox Stream Agent. An attacker must be able to machine-in-the-middle the Anbox Stream Agent from within an internal network before they can attempt to take advantage of this.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:canonical:anbox_cloud:*:*:*:*:*:*:*:* | 1.17.0 (including) | 1.23.1 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



