PT-2019-2586 · Apache+1 · Apache Qpid Proton+1
CVE-2019-0223
·
Publicado
2019-03-06
·
Atualizado
2024-03-30
CVSS v3.1
7.4
Alta
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Qpid Proton versions 0.9 through 0.27.0
Description
The issue is related to errors in the certificate authentication procedure, allowing a remote attacker to implement a man-in-the-middle attack and intercept TLS traffic by anonymously connecting to a peer node using TLS, even when configured to verify the peer certificate. This can be achieved when used with OpenSSL versions before 1.1.0.
Recommendations
For Apache Qpid Proton versions 0.9 through 0.27.0, consider disabling the use of TLS anonymous connections until a patch is available. Restrict access to the TLS configuration to minimize the risk of exploitation. Avoid using OpenSSL versions before 1.1.0 with Apache Qpid Proton to reduce the vulnerability to man-in-the-middle attacks.
Correção
Improper Certificate Validation
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Apache Qpid Proton
Openssl