CVE-2024-8287

Anbox Management Service, in versions 1.17.0 through 1.23.0, does not validate the TLS certificate provided to it by the Anbox Stream Agent. An attacker must be able to machine-in-the-middle the Anbox Stream Agent from within an internal network before they can attempt to take advantage of this.
Configurations

Configuration 1 (hide)

cpe:2.3:a:canonical:anbox_cloud:*:*:*:*:*:*:*:*

History

24 Sep 2024, 15:52

Type Values Removed Values Added
First Time Canonical
Canonical anbox Cloud
CPE cpe:2.3:a:canonical:anbox_cloud:*:*:*:*:*:*:*:*
References () https://bugs.launchpad.net/anbox-cloud/+bug/2077570 - () https://bugs.launchpad.net/anbox-cloud/+bug/2077570 - Vendor Advisory
References () https://discourse.ubuntu.com/t/anbox-cloud-1-23-1-has-been-released/48141 - () https://discourse.ubuntu.com/t/anbox-cloud-1-23-1-has-been-released/48141 - Release Notes
References () https://www.cve.org/CVERecord?id=CVE-2024-8287 - () https://www.cve.org/CVERecord?id=CVE-2024-8287 - Third Party Advisory

20 Sep 2024, 12:30

Type Values Removed Values Added
Summary
  • (es) El servicio de administración de Anbox, en las versiones 1.17.0 a 1.23.0, no valida el certificado TLS que le proporciona el agente de transmisión de Anbox. Un atacante debe poder acceder a Anbox Stream Agent desde una red interna antes de intentar aprovechar esta ventaja.

18 Sep 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-18 19:15

Updated : 2024-09-24 15:52


NVD link : CVE-2024-8287

Mitre link : CVE-2024-8287

CVE.ORG link : CVE-2024-8287


JSON object : View

Products Affected

canonical

  • anbox_cloud
CWE
CWE-295

Improper Certificate Validation