VDB
CVE-2019-0223
CVE-2019-0223
PUBLISHED
CVSS 7.400000095367432 HIGH
While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0.9 to 0.27.0 (C library and its language bindings) can connect to a peer anonymously using TLS *even when configured to verify the peer certificate* while used with OpenSSL versions before 1.1.0. This means that an undetected man in the middle attack could be constructed if an attacker can arrange to intercept TLS traffic.
EPSS 6.20% · 93.3th percentile
Risk Scores
CVSS 3.1
7.400000095367432
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Score
6.20%
93.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:18.04:LTS | qpid-proton | 0.14.0-5.1, 0.14.0-5.1ubuntu1, 0 |
| Ubuntu:16.04:LTS | qpid-proton | 0, 0.10-2, 0.7-2 |
Timeline
- Apr 23, 2019 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 28, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Mar 1, 2022 EPSS Score
- May 3, 2022 EPSS Score
- Jul 4, 2022 EPSS Score
- Sep 6, 2022 EPSS Score
- Nov 8, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2019-0223 third-party-advisory
- https://issues.apache.org/jira/browse/PROTON-2014 third-party-advisory
- https://qpid.apache.org/cves/CVE-2019-0223.html third-party-advisory
- https://gitbox.apache.org/repos/asf?p=qpid-proton.git;h=97c7733 third-party-advisory
- https://gitbox.apache.org/repos/asf?p=qpid-proton.git;h=159fac1 third-party-advisory
- https://gitbox.apache.org/repos/asf?p=qpid-proton.git;h=4aea0fd third-party-advisory
- https://gitbox.apache.org/repos/asf?p=qpid-proton.git;h=2d3ba8a third-party-advisory
- http://www.openwall.com/lists/oss-security/2019/04/23/4 third-party-advisory
- https://issues.apache.org/jira/browse/PROTON-2014?page=com.atlassian.jira.plugin.system.issuetabpanels%3Aall-tabpanel third-party-advisory
- https://lists.apache.org/thread.html/008ee5e78e5a090e1fcc5f6617f425e4e51d59f03d3eda2dd006df9f@%3Cusers.qpid.apache.org%3E third-party-advisory
- https://lists.apache.org/thread.html/3adb2f020f705b4fd453982992a68cd10f9d5ac728b699efdb73c1f5@%3Cdev.qpid.apache.org%3E third-party-advisory
- https://lists.apache.org/thread.html/49c83f0acce5ceaeffca51714ec2ba0f0199bcb8f99167181bba441b@%3Cdev.qpid.apache.org%3E third-party-advisory
- https://lists.apache.org/thread.html/914424e4d798a340f523b6169aaf39b626971d9bb00fcdeb1d5d6c0d@%3Ccommits.qpid.apache.org%3E third-party-advisory
- https://lists.apache.org/thread.html/d9c9a882a292e2defaed1f954528c916fb64497ce57db652727e39b0@%3Cannounce.apache.org%3E third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2019-0223 third-party-advisory