TLS Man in the Middle Vulnerability in Apache Qpid Proton
CVE-2019-0223
7.4HIGH
What is CVE-2019-0223?
A TLS vulnerability in Apache Qpid Proton allows an attacker to exploit a flaw where the library might connect to a peer anonymously, bypassing the verification of the peer certificate. This issue affects versions 0.9 through 0.27.0 when used with OpenSSL versions earlier than 1.1.0, permitting a man in the middle attack if the attacker can intercept the TLS traffic. This could lead to potential data breaches or unauthorized access to sensitive information.
Affected Version(s)
Apache Qpid Proton 0.9 to 0.27.0