First published: Sun Mar 11 2018(Updated: )
The Djelibeybi configuration examples for use of NGINX in SUSE Portus 2.3, when applied to certain configurations involving Docker Compose, have a Missing SSL Certificate Validation issue because no proxy_ssl_* directives are used.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SUSE Portus | =2.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-8059 is classified as a medium severity vulnerability that could lead to potential security risks in specific configurations.
To fix CVE-2018-8059, ensure that proxy_ssl_* directives are correctly implemented in your NGINX configuration for SUSE Portus 2.3.
The impact of CVE-2018-8059 is that it allows for potential man-in-the-middle attacks due to missing SSL certificate validation.
CVE-2018-8059 affects SUSE Portus version 2.3.0 when using certain Docker Compose configurations.
CVE-2018-8059 is primarily a server-side vulnerability that affects the configuration of the NGINX proxy server.