Description

Anbox Management Service, in versions 1.17.0 through 1.23.0, does not validate the TLS certificate provided to it by the Anbox Stream Agent. An attacker must be able to machine-in-the-middle the Anbox Stream Agent from within an internal network before they can attempt to take advantage of this.

INFO

Published Date :

2024-09-18T18:35:25.803Z

Last Modified :

2024-09-19T20:25:24.637Z

Source :

canonical
AFFECTED PRODUCTS

The following products are affected by CVE-2024-8287 vulnerability.

Vendors Products
Canonical
  • Anbox Cloud
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-8287.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact