PT-2016-5042 · Apache+1 · Apache Qpid Proton+1

Ken Giusti

·

Published

2016-04-12

·

Updated

2024-04-05

·

CVE-2016-2166

CVSS v3.1

6.5

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache Qpid Proton versions prior to 0.12.1
Description The issue is related to the improper use of an unencrypted connection for an amqps URI scheme when SSL support is unavailable in certain classes. This might allow attackers to obtain sensitive information or modify data. The affected classes include proton.reactor.Connector, proton.reactor.Container, and proton.utils.BlockingConnection.
Recommendations For versions prior to 0.12.1, update to version 0.12.1 or later to resolve the issue. As a temporary workaround, consider disabling the use of amqps URI schemes when SSL support is unavailable to minimize the risk of exploitation. Restrict access to sensitive information and data to prevent potential modification by unauthorized parties.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

ALT-PU-2016-3246
CVE-2016-2166
GHSA-F5CF-F7PX-XPMH
OPENSUSE-SU-2024:10217-1

Affected Products

Alt Linux
Apache Qpid Proton