5.8
CVSSv2

CVE-2019-0223

Published: 23/04/2019 Updated: 07/11/2023
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.4 | Impact Score: 5.2 | Exploitability Score: 2.2
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0.9 to 0.27.0 (C library and its language bindings) can connect to a peer anonymously using TLS *even when configured to verify the peer certificate* while used with OpenSSL versions prior to 1.1.0. This means that an undetected man in the middle attack could be constructed if an attacker can arrange to intercept TLS traffic.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache qpid

redhat jboss_amq_clients_2 -

redhat enterprise linux desktop 7.0

redhat enterprise linux server aus 7.2

redhat enterprise linux workstation 7.0

redhat enterprise linux server tus 7.2

redhat enterprise linux server 7.0

redhat enterprise linux server aus 6.6

redhat enterprise linux eus 6.7

redhat enterprise linux server aus 6.5

redhat enterprise linux server aus 6.4

redhat enterprise linux desktop 6.0

redhat enterprise linux server 6.0

redhat enterprise linux workstation 6.0

redhat enterprise linux server tus 7.3

redhat enterprise linux server aus 7.3

redhat enterprise linux server aus 7.4

redhat enterprise linux server tus 7.4

redhat enterprise linux eus 7.3

redhat enterprise linux eus 7.4

redhat enterprise linux eus 7.5

redhat satellite 6.3

redhat enterprise linux server aus 5.9

redhat enterprise linux server tus 7.6

redhat enterprise linux server aus 7.6

redhat enterprise linux eus 7.6

redhat satellite 6.4

redhat enterprise linux eus 7.2

redhat openstack 14

redhat openstack 13

redhat satellite 6.5

Vendor Advisories

Synopsis Important: AMQ Clients 231 release and security update Type/Severity Security Advisory: Important Topic Updated Red Hat AMQ Clients 231 packages are now availableRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS ...
Synopsis Moderate: qpid-proton security update Type/Severity Security Advisory: Moderate Topic An update for qpid-proton is now available for Red Hat OpenStack Platform14 (Rocky)Red Hat Product Security has rated this update as having a security impactof Moderate A Common Vulnerability Scoring System (CVS ...
Synopsis Important: qpid-proton security update Type/Severity Security Advisory: Important Topic An update for qpid-proton is now available for Red Hat Satellite 63 for RHEL 7Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVS ...
Synopsis Important: qpid-proton security update Type/Severity Security Advisory: Important Topic An update for qpid-proton is now available for Red Hat Satellite 65 for RHEL 7Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVS ...
Synopsis Moderate: qpid-proton security update Type/Severity Security Advisory: Moderate Topic An update for qpid-proton is now available for Red Hat OpenStack Platform 13 (Queens)Red Hat Product Security has rated this update as having a security impactof Moderate A Common Vulnerability Scoring System (C ...
Synopsis Moderate: qpid-proton security update Type/Severity Security Advisory: Moderate Topic An update for qpid-proton is now available for Red Hat OpenStack Platform14 (Rocky)Red Hat Product Security has rated this update as having a security impactof Moderate A Common Vulnerability Scoring System (CVS ...
Synopsis Important: qpid-proton security update Type/Severity Security Advisory: Important Topic An update for qpid-proton is now available for Satellite Tools 65Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score ...
Synopsis Important: qpid-proton security update Type/Severity Security Advisory: Important Topic An update for qpid-proton is now available for Red Hat Satellite 64 for RHEL 7Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVS ...
Impact: Important Public Date: 2019-04-23 CWE: CWE-295->CWE-300 Bugzilla: 1702439: CVE-2019-0223 qpi ...

Github Repositories

Create a Satellite host errata report (csv)

Create a Satellite host errata report (csv) To get a frequently report of installable Red Hat errata on a per host basis you can use this Python script Download it to your Satellite server or any other host where Python 27 is installed Table of Contents Prerequisites 1 Where to get the available API calls 2 Where to find the available JSON fields to query within the Pytho