While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0.9 to 0.27.0 (C library and its language bindings) can connect to a peer anonymously using TLS *even when configured to verify the peer certificate* while used with OpenSSL versions before 1.1.0. This means that an undetected man in the middle attack could be constructed if an attacker can arrange to intercept TLS traffic.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Apache
Subscribe
|
Qpid
Subscribe
|
|
Redhat
Subscribe
|
A Mq Clients
Subscribe
Cloudforms Managementengine
Subscribe
Enterprise Linux
Subscribe
Enterprise Linux Desktop
Subscribe
Enterprise Linux Eus
Subscribe
Enterprise Linux Server
Subscribe
Enterprise Linux Server Aus
Subscribe
Enterprise Linux Server Tus
Subscribe
Enterprise Linux Workstation
Subscribe
Jboss Amq Clients 2
Subscribe
Linux
Subscribe
Openstack
Subscribe
Openstack-optools
Subscribe
Rhel Satellite Tools
Subscribe
Satellite
Subscribe
Satellite Capsule
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-2590 | While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0.9 to 0.27.0 (C library and its language bindings) can connect to a peer anonymously using TLS *even when configured to verify the peer certificate* while used with OpenSSL versions before 1.1.0. This means that an undetected man in the middle attack could be constructed if an attacker can arrange to intercept TLS traffic. |
Github GHSA |
GHSA-5h6x-m52p-23ph | Withdrawn Advisory: Improper Certificate Validation in Apache Qpid Proton |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-04T17:44:15.919Z
Reserved: 2018-11-14T00:00:00
Link: CVE-2019-0223
No data.
Status : Modified
Published: 2019-04-23T16:29:00.467
Modified: 2024-11-21T04:16:31.753
Link: CVE-2019-0223
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA