6.5
CVSSv3

CVE-2016-2166

Published: 12/04/2016 Updated: 07/11/2023
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 4.2 | Exploitability Score: 2.2
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

The (1) proton.reactor.Connector, (2) proton.reactor.Container, and (3) proton.utils.BlockingConnection classes in Apache Qpid Proton prior to 0.12.1 improperly use an unencrypted connection for an amqps URI scheme when SSL support is unavailable, which might allow man-in-the-middle malicious users to obtain sensitive information or modify data via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

apache qpid proton

fedoraproject fedora 23

Vendor Advisories

The (1) protonreactorConnector, (2) protonreactorContainer, and (3) protonutilsBlockingConnection classes in Apache Qpid Proton before 0121 improperly use an unencrypted connection for an amqps URI scheme when SSL support is unavailable, which might allow man-in-the-middle attackers to obtain sensitive information or modify data via unspeci ...