PT-2016-5042 · Apache+1 · Apache Qpid Proton+1
Ken Giusti
·
Published
2016-04-12
·
Updated
2024-04-05
·
CVE-2016-2166
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Qpid Proton versions prior to 0.12.1
Description
The issue is related to the improper use of an unencrypted connection for an amqps URI scheme when SSL support is unavailable in certain classes. This might allow attackers to obtain sensitive information or modify data. The affected classes include proton.reactor.Connector, proton.reactor.Container, and proton.utils.BlockingConnection.
Recommendations
For versions prior to 0.12.1, update to version 0.12.1 or later to resolve the issue. As a temporary workaround, consider disabling the use of amqps URI schemes when SSL support is unavailable to minimize the risk of exploitation. Restrict access to sensitive information and data to prevent potential modification by unauthorized parties.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Apache Qpid Proton