HIGH7.5
GHSA-qrqr-3x5j-2xw9
Docker Authentication Bypass
Quick fix
GHSA-qrqr-3x5j-2xw9 — github.com/docker/docker: upgrade to the fixed version with the command below.
go get github.com/docker/docker@v17.06.0-ceDetails
An issue was discovered in Docker Moby before 17.06.0. The Docker engine validated a client TLS certificate using both the configured client CA root certificate and all system roots on non-Windows systems. This allowed a client with any domain validated certificate signed by a system-trusted root CA (as opposed to one signed by the configured CA root certificate) to authenticate.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/docker/docker
Introduced in:
0Fixed in: 17.06.0-ceFix
go get github.com/docker/docker@v17.06.0-ce