CVE-2024-8287
CVE-2024-8287
Título es
CVE-2024-8287
Mié, 18/09/2024 – 19:15
Tipo
CWE-295
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2024-8287
Descripción en
Anbox Management Service, in versions 1.17.0 through 1.23.0, does not validate the TLS certificate provided to it by the Anbox Stream Agent. An attacker must be able to machine-in-the-middle the Anbox Stream Agent from within an internal network before they can attempt to take advantage of this.
18/09/2024
18/09/2024
Vector CVSS:3.1
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Gravedad 3.1 (CVSS 3.1 Base Score)
7.50
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
HIGH
Referencias
Enviar en el boletín
Off
