Debian Qpid-Proton vulnerabilities
2 known vulnerabilities affecting debian/qpid-proton.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1LOW1
Vulnerabilities
Page 1 of 1
CVE-2019-0223P3HIGHCVSS 7.4fixed in qpid-proton 0.22.0-1 (bookworm)2019
CVE-2019-0223 [HIGH] CVE-2019-0223: qpid-proton - While investigating bug PROTON-2014, we discovered that under some circumstances...
While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0.9 to 0.27.0 (C library and its language bindings) can connect to a peer anonymously using TLS *even when configured to verify the peer certificate* while used with OpenSSL versions before 1.1.0. This means that an undetected man in the middle attack could
debian
CVE-2018-17187P3LOWCVSS 7.4fixed in qpid-proton 0.22.0-1 (bookworm)2018
CVE-2018-17187 [HIGH] CVE-2018-17187: qpid-proton - The Apache Qpid Proton-J transport includes an optional wrapper layer to perform...
The Apache Qpid Proton-J transport includes an optional wrapper layer to perform TLS, enabled by use of the 'transport.ssl(...)' methods. Unless a verification mode was explicitly configured, client and server modes previously defaulted as documented to not verifying a peer certificate, with options to configure this explicitly or select a certificate verificati
debian