CVE-2019-0223
published 2019-04-23CVE-2019-0223: While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0.9 to 0.27.0 (C library and its language…
PriorityP346high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
6.20%
92.7th percentile
While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0.9 to 0.27.0 (C library and its language bindings) can connect to a peer anonymously using TLS *even when configured to verify the peer certificate* while used with OpenSSL versions before 1.1.0. This means that an undetected man in the middle attack could be constructed if an attacker can arrange to intercept TLS traffic.
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | qpid | 0.9 – 0.27.0 | — |
| apache_software_foundation | apache_qpid_proton | — | — |
| debian | qpid-proton | < qpid-proton 0.22.0-1 (bookworm) | qpid-proton 0.22.0-1 (bookworm) |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv7.4HIGH
vendor_debian7.4HIGH
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
qpid-proton: TLS Man in the Middle Vulnerability
vendor_redhat·2019-04-23·CVSS 7.4
CVE-2019-0223 [HIGH] CWE-358 qpid-proton: TLS Man in the Middle Vulnerability
qpid-proton: TLS Man in the Middle Vulnerability
While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0.9 to 0.27.0 (C library and its language bindings) can connect to a peer anonymously using TLS *even when configured to verify the peer certificate* while used with OpenSSL versions before 1.1.0. This means that an undetected man in the middle attack could be constructed if an attacker can arrange to intercept TLS traffic.
A cryptographic weakness was discovered in qpid-proton's use of TLS. If the qpid-proton client was used without client certificates, it would accept an anonymous cipher offered by the server. A man-in-the-middle attacker could use this to silently intercept traffic that should have been encrypted.
Statement: Red
Debian
CVE-2019-0223: qpid-proton - While investigating bug PROTON-2014, we discovered that under some circumstances...
vendor_debian·2019·CVSS 7.4
CVE-2019-0223 [HIGH] CVE-2019-0223: qpid-proton - While investigating bug PROTON-2014, we discovered that under some circumstances...
While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0.9 to 0.27.0 (C library and its language bindings) can connect to a peer anonymously using TLS *even when configured to verify the peer certificate* while used with OpenSSL versions before 1.1.0. This means that an undetected man in the middle attack could be constructed if an attacker can arrange to intercept TLS traffic.
Scope: local
bookworm: resolved (fixed in 0.22.0-1)
bullseye: resolved (fixed in 0.22.0-1)
forky: resolved (fixed in 0.22.0-1)
sid: resolved (fixed in 0.22.0-1)
trixie: resolved (fixed in 0.22.0-1)
GHSA
Withdrawn Advisory: Improper Certificate Validation in Apache Qpid Proton
ghsa·2022-05-24
CVE-2019-0223 [HIGH] CWE-295 Withdrawn Advisory: Improper Certificate Validation in Apache Qpid Proton
Withdrawn Advisory: Improper Certificate Validation in Apache Qpid Proton
## Withdrawn Advisory
This advisory has been withdrawn because the vulnerability only affects the **Qpid Proton C library** and not `org.apache.qpid:proton-j`. This link has been maintained to preserve external references.
## Original Description
While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0.9 to 0.27.0 (C library and its language bindings) can connect to a peer anonymously using TLS *even when configured to verify the peer certificate* while used with OpenSSL versions before 1.1.0. This means that an undetected man in the middle attack could be constructed if an attacker can arrange to intercept TLS traffic.
GHSA
slixmpp Incorrect Access Control
ghsa·2022-05-13
CVE-2019-1000021 [HIGH] CWE-284 slixmpp Incorrect Access Control
slixmpp Incorrect Access Control
slixmpp version before commit 7cd73b594e8122dddf847953fcfc85ab4d316416 contains an incorrect Access Control vulnerability in XEP-0223 plugin (Persistent Storage of Private Data via PubSub) options profile, used for the configuration of default access model that can result in all of the contacts of the victim can see private data having been published to a PEP node. This attack appears to be exploitable if the user of this library publishes any private data on PEP, the node isn't configured to be private. This vulnerability appears to have been fixed in commit 7cd73b594e8122dddf847953fcfc85ab4d316416 which is included in slixmpp 1.4.2.
OSV
CVE-2019-0223: While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0
osv·2019-04-23·CVSS 7.4
CVE-2019-0223 [HIGH] CVE-2019-0223: While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0
While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0.9 to 0.27.0 (C library and its language bindings) can connect to a peer anonymously using TLS *even when configured to verify the peer certificate* while used with OpenSSL versions before 1.1.0. This means that an undetected man in the middle attack could be constructed if an attacker can arrange to intercept TLS traffic.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-0223 qpid-proton: TLS Man in the Middle Vulnerability
bugzilla·2019-04-23·CVSS 7.4
CVE-2019-0223 [HIGH] CVE-2019-0223 qpid-proton: TLS Man in the Middle Vulnerability
CVE-2019-0223 qpid-proton: TLS Man in the Middle Vulnerability
The TLS support in Apache Qpid Proton 0.9 - 0.27.0 when using OpenSSL prior to 1.1.0 can under some circumstances connect as a client to a TLS server that offers anonymous ciphers irrespective of whether the client was configured to verify the server's certificate or certificate against the hostname used to connect. This means that an undetected man in the middle attack could be constructed if an attacker can arrange to intercept TLS traffic. This
includes the Qpid Proton C library, and all language binding libraries using it. This attack will not work if client certificate authentication is
in use as anonymous ciphers cannot be used in this case.
References:
https://issues.apache.org/jira/browse/PROTON-2014
https://qpid.apa
Bugzilla
CVE-2019-0223 qpid-proton: TLS Man in the Middle Vulnerability [openstack-rdo]
bugzilla·2019-04-23·CVSS 7.4
CVE-2019-0223 [HIGH] CVE-2019-0223 qpid-proton: TLS Man in the Middle Vulnerability [openstack-rdo]
CVE-2019-0223 qpid-proton: TLS Man in the Middle Vulnerability [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Train+ RDO releases contains qpid-p
Bugzilla
CVE-2019-1000021 python-slixmpp: Improper acccess control in XEP-0223 plugin
bugzilla·2019-02-06·CVSS 7.5
CVE-2019-1000021 [HIGH] CVE-2019-1000021 python-slixmpp: Improper acccess control in XEP-0223 plugin
CVE-2019-1000021 python-slixmpp: Improper acccess control in XEP-0223 plugin
slixmpp version before commit 7cd73b594e8122dddf847953fcfc85ab4d316416 contains
an incorrect Access Control vulnerability in XEP-0223 plugin (Persistent Storage
of Private Data via PubSub) options profile, used for the configuration of
default access model that can result in all of the contacts of the victim can
see private data having been published to a PEP node. This attack appears to be
exploitable if the user of this library publishes any private data on PEP, the
node isn't configured to be private. This vulnerability appears to have been
fixed in commit 7cd73b594e8122dddf847953fcfc85ab4d316416 which is included in
slixmpp 1.4.2.
Upstream Issue:
https://xmpp.org/extensions/xep-0223.html#howitworks
Upstream
http://www.openwall.com/lists/oss-security/2019/04/23/4http://www.securityfocus.com/bid/108044https://access.redhat.com/errata/RHSA-2019:0886https://access.redhat.com/errata/RHSA-2019:1398https://access.redhat.com/errata/RHSA-2019:1399https://access.redhat.com/errata/RHSA-2019:1400https://access.redhat.com/errata/RHSA-2019:2777https://access.redhat.com/errata/RHSA-2019:2778https://access.redhat.com/errata/RHSA-2019:2779https://access.redhat.com/errata/RHSA-2019:2780https://access.redhat.com/errata/RHSA-2019:2781https://access.redhat.com/errata/RHSA-2019:2782https://issues.apache.org/jira/browse/PROTON-2014?page=com.atlassian.jira.plugin.system.issuetabpanels%3Aall-tabpanelhttps://lists.apache.org/thread.html/008ee5e78e5a090e1fcc5f6617f425e4e51d59f03d3eda2dd006df9f%40%3Cusers.qpid.apache.org%3Ehttps://lists.apache.org/thread.html/3adb2f020f705b4fd453982992a68cd10f9d5ac728b699efdb73c1f5%40%3Cdev.qpid.apache.org%3Ehttps://lists.apache.org/thread.html/49c83f0acce5ceaeffca51714ec2ba0f0199bcb8f99167181bba441b%40%3Cdev.qpid.apache.org%3Ehttps://lists.apache.org/thread.html/914424e4d798a340f523b6169aaf39b626971d9bb00fcdeb1d5d6c0d%40%3Ccommits.qpid.apache.org%3Ehttps://lists.apache.org/thread.html/d9c9a882a292e2defaed1f954528c916fb64497ce57db652727e39b0%40%3Cannounce.apache.org%3Ehttp://www.openwall.com/lists/oss-security/2019/04/23/4http://www.securityfocus.com/bid/108044https://access.redhat.com/errata/RHSA-2019:0886https://access.redhat.com/errata/RHSA-2019:1398https://access.redhat.com/errata/RHSA-2019:1399https://access.redhat.com/errata/RHSA-2019:1400https://access.redhat.com/errata/RHSA-2019:2777https://access.redhat.com/errata/RHSA-2019:2778https://access.redhat.com/errata/RHSA-2019:2779https://access.redhat.com/errata/RHSA-2019:2780https://access.redhat.com/errata/RHSA-2019:2781https://access.redhat.com/errata/RHSA-2019:2782https://issues.apache.org/jira/browse/PROTON-2014?page=com.atlassian.jira.plugin.system.issuetabpanels%3Aall-tabpanelhttps://lists.apache.org/thread.html/008ee5e78e5a090e1fcc5f6617f425e4e51d59f03d3eda2dd006df9f%40%3Cusers.qpid.apache.org%3Ehttps://lists.apache.org/thread.html/3adb2f020f705b4fd453982992a68cd10f9d5ac728b699efdb73c1f5%40%3Cdev.qpid.apache.org%3Ehttps://lists.apache.org/thread.html/49c83f0acce5ceaeffca51714ec2ba0f0199bcb8f99167181bba441b%40%3Cdev.qpid.apache.org%3Ehttps://lists.apache.org/thread.html/914424e4d798a340f523b6169aaf39b626971d9bb00fcdeb1d5d6c0d%40%3Ccommits.qpid.apache.org%3Ehttps://lists.apache.org/thread.html/d9c9a882a292e2defaed1f954528c916fb64497ce57db652727e39b0%40%3Cannounce.apache.org%3E
2019-04-23
Published