CVE-2024-8287

Anbox Management Service, in versions 1.17.0 through 1.23.0, does not validate the TLS certificate provided to it by the Anbox Stream Agent. An attacker must be able to machine-in-the-middle the Anbox Stream Agent from within an internal network before they can attempt to take advantage of this.
Configurations

Configuration 1 (hide)

cpe:2.3:a:canonical:anbox_cloud:*:*:*:*:*:*:*:*

History

24 Sep 2024, 15:52

Type Values Removed Values Added
CWE CWE-295
First Time Canonical anbox Cloud
Canonical
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
References () https://www.cve.org/CVERecord?id=CVE-2024-8287 - () https://www.cve.org/CVERecord?id=CVE-2024-8287 - Third Party Advisory
References () https://bugs.launchpad.net/anbox-cloud/+bug/2077570 - () https://bugs.launchpad.net/anbox-cloud/+bug/2077570 - Vendor Advisory
References () https://discourse.ubuntu.com/t/anbox-cloud-1-23-1-has-been-released/48141 - () https://discourse.ubuntu.com/t/anbox-cloud-1-23-1-has-been-released/48141 - Release Notes
CPE cpe:2.3:a:canonical:anbox_cloud:*:*:*:*:*:*:*:*

18 Sep 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-18 19:15

Updated : 2024-09-24 15:52


NVD link : CVE-2024-8287

Mitre link : CVE-2024-8287


JSON object : View

Products Affected

canonical

  • anbox_cloud
CWE
CWE-295

Improper Certificate Validation