CVE-2024-8287

Anbox Management Service, in versions 1.17.0 through 1.23.0, does not validate the TLS certificate provided to it by the Anbox Stream Agent. An attacker must be able to machine-in-the-middle the Anbox Stream Agent from within an internal network before they can attempt to take advantage of this.
Configurations

Configuration 1 (hide)

cpe:2.3:a:canonical:anbox_cloud:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-09-18 19:15

Updated : 2024-09-24 15:52


NVD link : CVE-2024-8287

Mitre link : CVE-2024-8287

CVE.ORG link : CVE-2024-8287


JSON object : View

Products Affected

canonical

  • anbox_cloud
CWE
CWE-295

Improper Certificate Validation