Docker Authentication Bypass
High severity
GitHub Reviewed
Published
Jan 31, 2024
to the GitHub Advisory Database
•
Updated Jul 8, 2024
Description
Published to the GitHub Advisory Database
Jan 31, 2024
Reviewed
Jan 31, 2024
Last updated
Jul 8, 2024
An issue was discovered in Docker Moby before 17.06.0. The Docker engine validated a client TLS certificate using both the configured client CA root certificate and all system roots on non-Windows systems. This allowed a client with any domain validated certificate signed by a system-trusted root CA (as opposed to one signed by the configured CA root certificate) to authenticate.
References