Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-2590 | While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0.9 to 0.27.0 (C library and its language bindings) can connect to a peer anonymously using TLS *even when configured to verify the peer certificate* while used with OpenSSL versions before 1.1.0. This means that an undetected man in the middle attack could be constructed if an attacker can arrange to intercept TLS traffic. |
Github GHSA |
GHSA-5h6x-m52p-23ph | Withdrawn Advisory: Improper Certificate Validation in Apache Qpid Proton |
No history.
Subscriptions
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-04T17:44:15.919Z
Reserved: 2018-11-14T00:00:00.000Z
Link: CVE-2019-0223
No data.
Status : Modified
Published: 2019-04-23T16:29:00.467
Modified: 2026-06-17T02:08:01.570
Link: CVE-2019-0223
OpenCVE Enrichment
No data.
-
CWE-300
Channel Accessible by Non-Endpoint
-
CWE-358
Improperly Implemented Security Check for Standard
- NVD-CWE-noinfo
EUVD
Github GHSA