TLS Vulnerability in Apache Qpid Proton-J Transport
CVE-2018-17187
What is CVE-2018-17187?
The Apache Qpid Proton-J transport has a vulnerability that stems from its optional TLS wrapper layer. In versions 0.3 to 0.29.0, the default configuration does not enforce peer certificate verification, which could expose users to Man In The Middle (MITM) attacks. Although users can configure the TLS transport to verify certificates, the hostname verification feature was not implemented in the affected versions. To mitigate this vulnerability, it is essential for users to upgrade to version 0.30.0 or later and ensure that the VerifyMode#VERIFY_PEER_NAME setting is enabled to reinforce hostname verification as the default.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Apache Qpid Proton-J Apache Qpid Proton-J 0.3 to 0.29.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved