Apache MINA SSLFilter security Issue
CVE-2019-0231

7.5HIGH

Key Information:

Vendor
Apache
Vendor
CVE Published:
1 October 2019

Summary

Handling of the close_notify SSL/TLS message does not lead to a connection closure, leading the server to retain the socket opened and to have the client potentially receive clear text messages afterward. Mitigation: 2.0.20 users should migrate to 2.0.21, 2.1.0 users should migrate to 2.1.1. This issue affects: Apache MINA.

Affected Version(s)

Apache MINA Apache MINA 2.1 2.1.0

Apache MINA Apache MINA 2.0 2.0.21

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered and reported by Oleksii Osypov.
.