CVE-2024-8287

Severity CVSS v4.0:
Pending analysis
Type:
CWE-295 Improper Certificate Validation
Publication date:
18/09/2024
Last modified:
24/09/2024

Description

Anbox Management Service, in versions 1.17.0 through 1.23.0, does not validate the TLS certificate provided to it by the Anbox Stream Agent. An attacker must be able to machine-in-the-middle the Anbox Stream Agent from within an internal network before they can attempt to take advantage of this.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:canonical:anbox_cloud:*:*:*:*:*:*:*:* 1.17.0 (including) 1.23.1 (excluding)