CVE-2019-0231 PUBLISHED

Handling of the close_notify SSL/TLS message does not lead to a connection closure, leading the server to retain the socket opened and to have the client potentially receive clear text messages afterward. Mitigation: 2.0.20 users should migrate to 2.0.21, 2.1.0 users should migrate to 2.1.1. This issue affects: Apache MINA.

EPSS 0.71% · 72.0th percentile

Risk Scores

EPSS Score
0.71%
72.0th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSmina0, 1.1.7.dfsg-13
Ubuntu:18.04:LTSmina22.0.16-2, 0
Ubuntu:16.04:LTSmina22.0.9-2, 0, 2.0.7+dfsg-2
Ubuntu:18.04:LTSmina1.1.7.dfsg-11, 0, 1.1.7.dfsg-12
Ubuntu:16.04:LTSmina0, 1.1.7.dfsg-11
Ubuntu:24.04:LTSmina1.1.7.dfsg-13, 0, 1.1.7.dfsg-13ubuntu1
Ubuntu:22.04:LTSmina1.1.7.dfsg-13, 0
Ubuntu:20.04:LTSmina20, 2.0.19-2

Timeline

References

Open in Interactive Console →