CVE Vulnerabilities

CVE-2017-18641

Improper Authentication

Published: Feb 10, 2020 | Modified: Feb 12, 2020
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

In LXC 2.0, many template scripts download code over cleartext HTTP, and omit a digital-signature check, before running it to bootstrap containers.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Lxc Linuxcontainers 2.0.0 (including) 2.0.0 (including)
Lxc Ubuntu trusty *
Lxc Ubuntu upstream *
Lxc Ubuntu xenial *
Lxc-templates Ubuntu bionic *
Lxc-templates Ubuntu eoan *
Lxc-templates Ubuntu groovy *
Lxc-templates Ubuntu hirsute *
Lxc-templates Ubuntu impish *
Lxc-templates Ubuntu kinetic *
Lxc-templates Ubuntu lunar *
Lxc-templates Ubuntu mantic *
Lxc-templates Ubuntu trusty *

Potential Mitigations

References