Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-49068 | Anbox Management Service, in versions 1.17.0 through 1.23.0, does not validate the TLS certificate provided to it by the Anbox Stream Agent. An attacker must be able to machine-in-the-middle the Anbox Stream Agent from within an internal network before they can attempt to take advantage of this. |
Thu, 19 Sep 2024 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Canonical
Canonical anbox Cloud |
|
| CPEs | cpe:2.3:a:canonical:anbox_cloud:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Canonical
Canonical anbox Cloud |
|
| Metrics |
ssvc
|
Wed, 18 Sep 2024 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 18 Sep 2024 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Anbox Management Service, in versions 1.17.0 through 1.23.0, does not validate the TLS certificate provided to it by the Anbox Stream Agent. An attacker must be able to machine-in-the-middle the Anbox Stream Agent from within an internal network before they can attempt to take advantage of this. | |
| Weaknesses | CWE-295 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2024-09-19T20:25:24.637Z
Reserved: 2024-08-28T19:43:49.942Z
Link: CVE-2024-8287
Updated: 2024-09-19T20:25:13.106Z
Status : Analyzed
Published: 2024-09-18T19:15:41.073
Modified: 2024-09-24T15:52:38.047
Link: CVE-2024-8287
No data.
OpenCVE Enrichment
No data.
EUVD