While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0.9 to 0.27.0 (C library and its language bindings) can connect to a peer anonymously using TLS *even when configured to verify the peer certificate* while used with OpenSSL versions before 1.1.0. This means that an undetected man in the middle attack could be constructed if an attacker can arrange to intercept TLS traffic.
Metrics
No CVSS v4.0
Attack Vector Network
Attack Complexity High
Privileges Required None
Scope Unchanged
Confidentiality Impact High
Integrity Impact High
Availability Impact None
User Interaction None
Attack Vector Network
Attack Complexity High
Privileges Required None
Scope Unchanged
Confidentiality Impact High
Integrity Impact High
Availability Impact None
User Interaction None
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact None
This CVE is not in the KEV list.
The EPSS score is 0.00407.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
| Vendors | Products |
|---|---|
|
Apache
Subscribe
|
Qpid
Subscribe
|
|
Redhat
Subscribe
|
A Mq Clients
Subscribe
Cloudforms Managementengine
Subscribe
Enterprise Linux
Subscribe
Enterprise Linux Desktop
Subscribe
Enterprise Linux Eus
Subscribe
Enterprise Linux Server
Subscribe
Enterprise Linux Server Aus
Subscribe
Enterprise Linux Server Tus
Subscribe
Enterprise Linux Workstation
Subscribe
Jboss Amq Clients 2
Subscribe
Linux
Subscribe
Openstack
Subscribe
Openstack-optools
Subscribe
Rhel Satellite Tools
Subscribe
Satellite
Subscribe
Satellite Capsule
Subscribe
|
Configuration 1 [-]
|
Configuration 2 [-]
| AND |
|
Configuration 3 [-]
|
| Package | CPE | Advisory | Released Date |
|---|---|---|---|
| AMQ Clients 2.y for RHEL 6 | |||
| qpid-proton-0:0.27.0-3.el6 | cpe:/a:redhat:a_mq_clients:2::el6 | RHSA-2019:0886 | 2019-04-25T00:00:00Z |
| AMQ Clients 2.y for RHEL 7 | |||
| qpid-proton-0:0.27.0-3.el7 | cpe:/a:redhat:a_mq_clients:2::el7 | RHSA-2019:0886 | 2019-04-25T00:00:00Z |
| CloudForms Management Engine 5.11 | |||
| ansible-runner-0:1.3.4-2.el8ar | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| ansible-tower-0:3.5.2-1.el8at | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| cfme-0:5.11.0.28-1.el8cf | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| cfme-amazon-smartstate-0:5.11.0.28-1.el8cf | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| cfme-appliance-0:5.11.0.28-1.el8cf | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| cfme-gemset-0:5.11.0.28-1.el8cf | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| ovirt-ansible-cluster-upgrade-0:1.1.13-1.el8ev | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| ovirt-ansible-disaster-recovery-0:1.2.0-1.el8ev | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| ovirt-ansible-engine-setup-0:1.1.9-1.el8ev | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| ovirt-ansible-hosted-engine-setup-0:1.0.26-1.el8ev | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| ovirt-ansible-image-template-0:1.1.11-1.el8ev | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| ovirt-ansible-infra-0:1.1.12-1.el8ev | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| ovirt-ansible-manageiq-0:1.1.14-1.el8ev | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| ovirt-ansible-repositories-0:1.1.5-1.el8ev | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| ovirt-ansible-roles-0:1.1.7-2.el8ev | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| ovirt-ansible-shutdown-env-0:1.0.3-1.el8ev | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| ovirt-ansible-vm-infra-0:1.1.19-1.el8ev | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| prince-0:12.4-1.el8cf | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| python3-ovirt-engine-sdk4-0:4.3.2-1.el8ev | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| python-bambou-0:3.0.1-2.el8cf | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| python-colorama-0:0.4.1-1.el8ost | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| python-daemon-0:2.1.2-9.el8ar | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| python-funcsigs-0:1.0.2-3.el8ost | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| python-future-0:0.16.0-1.el8cf | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| python-lockfile-1:0.11.0-8.el8ar | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| python-mock-0:2.0.0-11.el8ost | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| python-pbr-0:5.1.2-2.el8ost | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| python-pexpect-0:4.6-2.el8ar | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| python-psutil-0:5.4.3-5.el8ar | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| python-pylxca-0:2.1.1-2.el8cf | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| python-requests-toolbelt-0:0.8.0-2.el8cf | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| python-tabulate-0:0.8.2-1.el8cf | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| python-vspk-0:5.3.2-2.el8cf | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| qpid-proton-0:0.28.0-1.el8 | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| repmgr10-0:4.0.6-3.el8cf | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| rubygem-bcrypt-0:3.1.13-1.el8cf | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| rubygem-byebug-0:11.0.1-1.el8cf | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| rubygem-escape_utils-0:1.2.1-1.el8cf | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| rubygem-ffi-0:1.9.25-1.el8cf | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| rubygem-hamlit-0:2.8.10-1.el8cf | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| rubygem-http_parser.rb-0:0.6.0-1.el8cf | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| rubygem-linux_block_device-0:0.2.1-1.el8cf | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| rubygem-memory_buffer-0:0.1.0-2.el8cf | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| rubygem-nio4r-0:2.4.0-1.el8cf | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| rubygem-nokogiri-0:1.8.5-1.el8cf | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| rubygem-ovirt-engine-sdk4-0:4.3.0-1.el8cf | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| rubygem-puma-0:3.7.1-1.el8cf | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| rubygem-qpid_proton-0:0.26.0-1.el8cf | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| rubygem-rugged-0:0.28.2-1.el8cf | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| rubygem-sassc-0:2.0.1-1.el8cf | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| rubygem-sqlite3-0:1.3.13-2.el8cf | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| rubygem-surro-gate-0:1.0.5-1.el8cf | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| rubygem-unf_ext-0:0.0.7.6-1.el8cf | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| rubygem-websocket-driver-0:0.6.5-1.el8cf | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| smem-0:1.4-1.el8cf | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| v2v-conversion-host-0:1.14.2-1.el8ev | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| wmi-0:1.3.14-8.el8cf | cpe:/a:redhat:cloudforms_managementengine:5.11::el8 | RHBA-2019:4199 | 2019-12-12T00:00:00Z |
| Red Hat OpenStack Platform 13.0 (Queens) | |||
| jsoncpp-0:1.7.7-1.el7 | cpe:/a:redhat:openstack:13::el7 | RHSA-2019:1400 | 2019-06-06T00:00:00Z |
| qpid-proton-0:0.27.0-3.el7 | cpe:/a:redhat:openstack:13::el7 | RHSA-2019:1400 | 2019-06-06T00:00:00Z |
| Red Hat OpenStack Platform 14.0 Operational Tools for RHEL 7 | |||
| qpid-proton-0:0.27.0-3.el7 | cpe:/a:redhat:openstack-optools:14::el7 | RHSA-2019:1398 | 2019-06-06T00:00:00Z |
| Red Hat OpenStack Platform 14.0 (Rocky) | |||
| qpid-proton-0:0.27.0-3.el7 | cpe:/a:redhat:openstack:14::el7 | RHSA-2019:1399 | 2019-06-06T00:00:00Z |
| Red Hat Satellite 6.3 for RHEL 7 | |||
| qpid-proton-0:0.16.0-14.el7sat | cpe:/a:redhat:satellite:6.3::el7 | RHSA-2019:2779 | 2019-09-17T00:00:00Z |
| qpid-proton-0:0.16.0-14.el7sat | cpe:/a:redhat:satellite_capsule:6.3::el7 | RHSA-2019:2779 | 2019-09-17T00:00:00Z |
| Red Hat Satellite 6.4 for RHEL 7 | |||
| qpid-proton-0:0.16.0-14.el7sat | cpe:/a:redhat:satellite:6.4::el7 | RHSA-2019:2778 | 2019-09-17T00:00:00Z |
| qpid-proton-0:0.16.0-14.el7sat | cpe:/a:redhat:satellite_capsule:6.4::el7 | RHSA-2019:2778 | 2019-09-17T00:00:00Z |
| Red Hat Satellite 6.5 for RHEL 7 | |||
| qpid-proton-0:0.28.0-1.el7 | cpe:/a:redhat:satellite:6.5::el7 | RHSA-2019:2777 | 2019-09-17T00:00:00Z |
| qpid-proton-0:0.28.0-1.el7 | cpe:/a:redhat:satellite_capsule:6.5::el7 | RHSA-2019:2777 | 2019-09-17T00:00:00Z |
| Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS | |||
| qpid-proton-0:0.28.0-1.el7 | cpe:/o:redhat:enterprise_linux:7::hypervisor | RHSA-2019:2780 | 2019-09-17T00:00:00Z |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | |||
| qpid-proton-0:0.28.0-1.el7 | cpe:/o:redhat:enterprise_linux:7::hypervisor | RHSA-2019:2780 | 2019-09-17T00:00:00Z |
| qpid-proton-0:0.16.0-14.el7sat | cpe:/o:redhat:enterprise_linux:7::hypervisor | RHSA-2019:2782 | 2019-09-20T00:00:00Z |
| Satellite Tools 6.3 for RHEL 5.9.AUS | |||
| qpid-proton-0:0.9-22.el5 | cpe:/a:redhat:rhel_satellite_tools:6.3::el5 | RHSA-2019:2781 | 2019-09-20T00:00:00Z |
| Satellite Tools 6.3 for RHEL 5.ELS | |||
| qpid-proton-0:0.9-22.el5 | cpe:/a:redhat:rhel_satellite_tools:6.3::el5 | RHSA-2019:2781 | 2019-09-20T00:00:00Z |
| Satellite Tools 6.3 for RHEL 6 | |||
| qpid-proton-0:0.16.0-14.el6sat | cpe:/a:redhat:rhel_satellite_tools:6.3::el6 | RHSA-2019:2781 | 2019-09-20T00:00:00Z |
| Satellite Tools 6.3 for RHEL 6.4.AUS | |||
| qpid-proton-0:0.16.0-14.el6sat | cpe:/a:redhat:rhel_satellite_tools:6.3::el6 | RHSA-2019:2781 | 2019-09-20T00:00:00Z |
| Satellite Tools 6.3 for RHEL 6.5.AUS | |||
| qpid-proton-0:0.16.0-14.el6sat | cpe:/a:redhat:rhel_satellite_tools:6.3::el6 | RHSA-2019:2781 | 2019-09-20T00:00:00Z |
| Satellite Tools 6.3 for RHEL 6.6.AUS | |||
| qpid-proton-0:0.16.0-14.el6sat | cpe:/a:redhat:rhel_satellite_tools:6.3::el6 | RHSA-2019:2781 | 2019-09-20T00:00:00Z |
| Satellite Tools 6.3 for RHEL 6.7.EUS | |||
| qpid-proton-0:0.16.0-14.el6sat | cpe:/a:redhat:rhel_satellite_tools:6.3::el6 | RHSA-2019:2781 | 2019-09-20T00:00:00Z |
| Satellite Tools 6.3 for RHEL 7 | |||
| qpid-proton-0:0.16.0-14.el7sat | cpe:/a:redhat:rhel_satellite_tools:6.3::el7 | RHSA-2019:2781 | 2019-09-20T00:00:00Z |
| Satellite Tools 6.3 for RHEL 7.2.AUS | |||
| qpid-proton-0:0.16.0-14.el7sat | cpe:/a:redhat:rhel_satellite_tools:6.3::el7 | RHSA-2019:2781 | 2019-09-20T00:00:00Z |
| Satellite Tools 6.3 for RHEL 7.2.E4S | |||
| qpid-proton-0:0.16.0-14.el7sat | cpe:/a:redhat:rhel_satellite_tools:6.3::el7 | RHSA-2019:2781 | 2019-09-20T00:00:00Z |
| Satellite Tools 6.3 for RHEL 7.2.EUS | |||
| qpid-proton-0:0.16.0-14.el7sat | cpe:/a:redhat:rhel_satellite_tools:6.3::el7 | RHSA-2019:2781 | 2019-09-20T00:00:00Z |
| Satellite Tools 6.3 for RHEL 7.3.AUS | |||
| qpid-proton-0:0.16.0-14.el7sat | cpe:/a:redhat:rhel_satellite_tools:6.3::el7 | RHSA-2019:2781 | 2019-09-20T00:00:00Z |
| Satellite Tools 6.3 for RHEL 7.3.E4S | |||
| qpid-proton-0:0.16.0-14.el7sat | cpe:/a:redhat:rhel_satellite_tools:6.3::el7 | RHSA-2019:2781 | 2019-09-20T00:00:00Z |
| Satellite Tools 6.3 for RHEL 7.3.EUS | |||
| qpid-proton-0:0.16.0-14.el7sat | cpe:/a:redhat:rhel_satellite_tools:6.3::el7 | RHSA-2019:2781 | 2019-09-20T00:00:00Z |
| Satellite Tools 6.3 for RHEL 7.4.AUS | |||
| qpid-proton-0:0.16.0-14.el7sat | cpe:/a:redhat:rhel_satellite_tools:6.3::el7 | RHSA-2019:2781 | 2019-09-20T00:00:00Z |
| Satellite Tools 6.3 for RHEL 7.4.E4S | |||
| qpid-proton-0:0.16.0-14.el7sat | cpe:/a:redhat:rhel_satellite_tools:6.3::el7 | RHSA-2019:2781 | 2019-09-20T00:00:00Z |
| Satellite Tools 6.3 for RHEL 7.4.EUS | |||
| qpid-proton-0:0.16.0-14.el7sat | cpe:/a:redhat:rhel_satellite_tools:6.3::el7 | RHSA-2019:2781 | 2019-09-20T00:00:00Z |
| Satellite Tools 6.3 for RHEL 7.5.EUS | |||
| qpid-proton-0:0.16.0-14.el7sat | cpe:/a:redhat:rhel_satellite_tools:6.3::el7 | RHSA-2019:2781 | 2019-09-20T00:00:00Z |
| Satellite Tools 6.3 for RHEL 7.6.AUS | |||
| qpid-proton-0:0.16.0-14.el7sat | cpe:/a:redhat:rhel_satellite_tools:6.3::el7 | RHSA-2019:2781 | 2019-09-20T00:00:00Z |
| Satellite Tools 6.3 for RHEL 7.6.E4S | |||
| qpid-proton-0:0.16.0-14.el7sat | cpe:/a:redhat:rhel_satellite_tools:6.3::el7 | RHSA-2019:2781 | 2019-09-20T00:00:00Z |
| Satellite Tools 6.3 for RHEL 7.6.EUS | |||
| qpid-proton-0:0.16.0-14.el7sat | cpe:/a:redhat:rhel_satellite_tools:6.3::el7 | RHSA-2019:2781 | 2019-09-20T00:00:00Z |
| Satellite Tools 6.4 for RHEL 5.9.AUS | |||
| qpid-proton-0:0.9-22.el5 | cpe:/a:redhat:rhel_satellite_tools:6.4::el5 | RHSA-2019:2782 | 2019-09-20T00:00:00Z |
| Satellite Tools 6.4 for RHEL 5.ELS | |||
| qpid-proton-0:0.9-22.el5 | cpe:/a:redhat:rhel_satellite_tools:6.4::el5 | RHSA-2019:2782 | 2019-09-20T00:00:00Z |
| Satellite Tools 6.4 for RHEL 6 | |||
| qpid-proton-0:0.16.0-14.el6sat | cpe:/a:redhat:rhel_satellite_tools:6.4::el6 | RHSA-2019:2782 | 2019-09-20T00:00:00Z |
| Satellite Tools 6.4 for RHEL 6.7.EUS | |||
| qpid-proton-0:0.16.0-14.el6sat | cpe:/a:redhat:rhel_satellite_tools:6.4::el6 | RHSA-2019:2782 | 2019-09-20T00:00:00Z |
| Satellite Tools 6.4 for RHEL 7 | |||
| qpid-proton-0:0.16.0-14.el7sat | cpe:/a:redhat:rhel_satellite_tools:6.4::el7 | RHSA-2019:2782 | 2019-09-20T00:00:00Z |
| Satellite Tools 6.4 for RHEL 7.2.AUS | |||
| qpid-proton-0:0.16.0-14.el7sat | cpe:/a:redhat:rhel_satellite_tools:6.4::el7 | RHSA-2019:2782 | 2019-09-20T00:00:00Z |
| Satellite Tools 6.4 for RHEL 7.2.E4S | |||
| qpid-proton-0:0.16.0-14.el7sat | cpe:/a:redhat:rhel_satellite_tools:6.4::el7 | RHSA-2019:2782 | 2019-09-20T00:00:00Z |
| Satellite Tools 6.4 for RHEL 7.2.TUS | |||
| qpid-proton-0:0.16.0-14.el7sat | cpe:/a:redhat:rhel_satellite_tools:6.4::el7 | RHSA-2019:2782 | 2019-09-20T00:00:00Z |
| Satellite Tools 6.4 for RHEL 7.3.AUS | |||
| qpid-proton-0:0.16.0-14.el7sat | cpe:/a:redhat:rhel_satellite_tools:6.4::el7 | RHSA-2019:2782 | 2019-09-20T00:00:00Z |
| Satellite Tools 6.4 for RHEL 7.3.E4S | |||
| qpid-proton-0:0.16.0-14.el7sat | cpe:/a:redhat:rhel_satellite_tools:6.4::el7 | RHSA-2019:2782 | 2019-09-20T00:00:00Z |
| Satellite Tools 6.4 for RHEL 7.3.TUS | |||
| qpid-proton-0:0.16.0-14.el7sat | cpe:/a:redhat:rhel_satellite_tools:6.4::el7 | RHSA-2019:2782 | 2019-09-20T00:00:00Z |
| Satellite Tools 6.4 for RHEL 7.4.AUS | |||
| qpid-proton-0:0.16.0-14.el7sat | cpe:/a:redhat:rhel_satellite_tools:6.4::el7 | RHSA-2019:2782 | 2019-09-20T00:00:00Z |
| Satellite Tools 6.4 for RHEL 7.4.E4S | |||
| qpid-proton-0:0.16.0-14.el7sat | cpe:/a:redhat:rhel_satellite_tools:6.4::el7 | RHSA-2019:2782 | 2019-09-20T00:00:00Z |
| Satellite Tools 6.4 for RHEL 7.4.EUS | |||
| qpid-proton-0:0.16.0-14.el7sat | cpe:/a:redhat:rhel_satellite_tools:6.4::el7 | RHSA-2019:2782 | 2019-09-20T00:00:00Z |
| Satellite Tools 6.4 for RHEL 7.4.TUS | |||
| qpid-proton-0:0.16.0-14.el7sat | cpe:/a:redhat:rhel_satellite_tools:6.4::el7 | RHSA-2019:2782 | 2019-09-20T00:00:00Z |
| Satellite Tools 6.4 for RHEL 7.5.EUS | |||
| qpid-proton-0:0.16.0-14.el7sat | cpe:/a:redhat:rhel_satellite_tools:6.4::el7 | RHSA-2019:2782 | 2019-09-20T00:00:00Z |
| Satellite Tools 6.4 for RHEL 7.6.AUS | |||
| qpid-proton-0:0.16.0-14.el7sat | cpe:/a:redhat:rhel_satellite_tools:6.4::el7 | RHSA-2019:2782 | 2019-09-20T00:00:00Z |
| Satellite Tools 6.4 for RHEL 7.6.E4S | |||
| qpid-proton-0:0.16.0-14.el7sat | cpe:/a:redhat:rhel_satellite_tools:6.4::el7 | RHSA-2019:2782 | 2019-09-20T00:00:00Z |
| Satellite Tools 6.4 for RHEL 7.6.EUS | |||
| qpid-proton-0:0.16.0-14.el7sat | cpe:/a:redhat:rhel_satellite_tools:6.4::el7 | RHSA-2019:2782 | 2019-09-20T00:00:00Z |
| Satellite Tools 6.4 for RHEL 7.6.TUS | |||
| qpid-proton-0:0.16.0-14.el7sat | cpe:/a:redhat:rhel_satellite_tools:6.4::el7 | RHSA-2019:2782 | 2019-09-20T00:00:00Z |
| Satellite Tools 6.5 for RHEL 5.9.AUS | |||
| qpid-proton-0:0.9-22.el5 | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:2780 | 2019-09-17T00:00:00Z |
| Satellite Tools 6.5 for RHEL 5.ELS | |||
| qpid-proton-0:0.9-22.el5 | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:2780 | 2019-09-17T00:00:00Z |
| Satellite Tools 6.5 for RHEL 6 | |||
| qpid-proton-0:0.16.0-14.el6sat | cpe:/a:redhat:rhel_satellite_tools:6.5::el6 | RHSA-2019:2780 | 2019-09-17T00:00:00Z |
| Satellite Tools 6.5 for RHEL 7 | |||
| qpid-proton-0:0.28.0-1.el7 | cpe:/a:redhat:rhel_satellite_tools:6.5::el7 | RHSA-2019:2780 | 2019-09-17T00:00:00Z |
| Satellite Tools 6.5 for RHEL 7.2.AUS | |||
| qpid-proton-0:0.28.0-1.el7 | cpe:/a:redhat:rhel_satellite_tools:6.5::el7 | RHSA-2019:2780 | 2019-09-17T00:00:00Z |
| Satellite Tools 6.5 for RHEL 7.2.E4S | |||
| qpid-proton-0:0.28.0-1.el7 | cpe:/a:redhat:rhel_satellite_tools:6.5::el7 | RHSA-2019:2780 | 2019-09-17T00:00:00Z |
| Satellite Tools 6.5 for RHEL 7.2.TUS | |||
| qpid-proton-0:0.28.0-1.el7 | cpe:/a:redhat:rhel_satellite_tools:6.5::el7 | RHSA-2019:2780 | 2019-09-17T00:00:00Z |
| Satellite Tools 6.5 for RHEL 7.3.AUS | |||
| qpid-proton-0:0.28.0-1.el7 | cpe:/a:redhat:rhel_satellite_tools:6.5::el7 | RHSA-2019:2780 | 2019-09-17T00:00:00Z |
| Satellite Tools 6.5 for RHEL 7.3.E4S | |||
| qpid-proton-0:0.28.0-1.el7 | cpe:/a:redhat:rhel_satellite_tools:6.5::el7 | RHSA-2019:2780 | 2019-09-17T00:00:00Z |
| Satellite Tools 6.5 for RHEL 7.3.TUS | |||
| qpid-proton-0:0.28.0-1.el7 | cpe:/a:redhat:rhel_satellite_tools:6.5::el7 | RHSA-2019:2780 | 2019-09-17T00:00:00Z |
| Satellite Tools 6.5 for RHEL 7.4.AUS | |||
| qpid-proton-0:0.28.0-1.el7 | cpe:/a:redhat:rhel_satellite_tools:6.5::el7 | RHSA-2019:2780 | 2019-09-17T00:00:00Z |
| Satellite Tools 6.5 for RHEL 7.4.E4S | |||
| qpid-proton-0:0.28.0-1.el7 | cpe:/a:redhat:rhel_satellite_tools:6.5::el7 | RHSA-2019:2780 | 2019-09-17T00:00:00Z |
| Satellite Tools 6.5 for RHEL 7.4.EUS | |||
| qpid-proton-0:0.28.0-1.el7 | cpe:/a:redhat:rhel_satellite_tools:6.5::el7 | RHSA-2019:2780 | 2019-09-17T00:00:00Z |
| Satellite Tools 6.5 for RHEL 7.4.TUS | |||
| qpid-proton-0:0.28.0-1.el7 | cpe:/a:redhat:rhel_satellite_tools:6.5::el7 | RHSA-2019:2780 | 2019-09-17T00:00:00Z |
| Satellite Tools 6.5 for RHEL 7.5.EUS | |||
| qpid-proton-0:0.28.0-1.el7 | cpe:/a:redhat:rhel_satellite_tools:6.5::el7 | RHSA-2019:2780 | 2019-09-17T00:00:00Z |
| Satellite Tools 6.5 for RHEL 7.6.AUS | |||
| qpid-proton-0:0.28.0-1.el7 | cpe:/a:redhat:rhel_satellite_tools:6.5::el7 | RHSA-2019:2780 | 2019-09-17T00:00:00Z |
| Satellite Tools 6.5 for RHEL 7.6.E4S | |||
| qpid-proton-0:0.28.0-1.el7 | cpe:/a:redhat:rhel_satellite_tools:6.5::el7 | RHSA-2019:2780 | 2019-09-17T00:00:00Z |
| Satellite Tools 6.5 for RHEL 7.6.EUS | |||
| qpid-proton-0:0.28.0-1.el7 | cpe:/a:redhat:rhel_satellite_tools:6.5::el7 | RHSA-2019:2780 | 2019-09-17T00:00:00Z |
| Satellite Tools 6.5 for RHEL 7.6.TUS | |||
| qpid-proton-0:0.28.0-1.el7 | cpe:/a:redhat:rhel_satellite_tools:6.5::el7 | RHSA-2019:2780 | 2019-09-17T00:00:00Z |
| Satellite Tools 6.5 for RHEL 8 | |||
| qpid-proton-0:0.28.0-1.el8 | cpe:/a:redhat:rhel_satellite_tools:6.5::el8 | RHSA-2019:2780 | 2019-09-17T00:00:00Z |
No data.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-2590 | While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0.9 to 0.27.0 (C library and its language bindings) can connect to a peer anonymously using TLS *even when configured to verify the peer certificate* while used with OpenSSL versions before 1.1.0. This means that an undetected man in the middle attack could be constructed if an attacker can arrange to intercept TLS traffic. |
Github GHSA |
GHSA-5h6x-m52p-23ph | Withdrawn Advisory: Improper Certificate Validation in Apache Qpid Proton |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-04T17:44:15.919Z
Reserved: 2018-11-14T00:00:00
Link: CVE-2019-0223
No data.
Status : Modified
Published: 2019-04-23T16:29:00.467
Modified: 2024-11-21T04:16:31.753
Link: CVE-2019-0223
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA