Описание
The (1) proton.reactor.Connector, (2) proton.reactor.Container, and (3) proton.utils.BlockingConnection classes in Apache Qpid Proton before 0.12.1 improperly use an unencrypted connection for an amqps URI scheme when SSL support is unavailable, which might allow man-in-the-middle attackers to obtain sensitive information or modify data via unspecified vectors.
Отчет
This issue affects the versions of qpid-proton as shipped with Red Hat Satellite version 6. Red Hat Product Security has rated this issue as having Moderate security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux OpenStack Platform 6 (Juno) | qpid-proton | Not affected | ||
| Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) | qpid-proton | Not affected | ||
| Red Hat Enterprise MRG 3 | qpid-proton | Not affected | ||
| Red Hat OpenStack Platform 8 (Liberty) | qpid-proton | Not affected | ||
| Red Hat Satellite 6 | python-qpid-proton | Not affected | ||
| Red Hat Satellite 6.3 for RHEL 7 | createrepo_c | Fixed | RHBA-2018:0337 | 21.02.2018 |
| Red Hat Satellite 6.3 for RHEL 7 | facter | Fixed | RHBA-2018:0337 | 21.02.2018 |
| Red Hat Satellite 6.3 for RHEL 7 | gofer | Fixed | RHBA-2018:0337 | 21.02.2018 |
| Red Hat Satellite 6.3 for RHEL 7 | hiera | Fixed | RHBA-2018:0337 | 21.02.2018 |
| Red Hat Satellite 6.3 for RHEL 7 | kobo | Fixed | RHBA-2018:0337 | 21.02.2018 |
Показывать по
Дополнительная информация
Статус:
EPSS
4.3 Medium
CVSS2
Связанные уязвимости
The (1) proton.reactor.Connector, (2) proton.reactor.Container, and (3) proton.utils.BlockingConnection classes in Apache Qpid Proton before 0.12.1 improperly use an unencrypted connection for an amqps URI scheme when SSL support is unavailable, which might allow man-in-the-middle attackers to obtain sensitive information or modify data via unspecified vectors.
The (1) proton.reactor.Connector, (2) proton.reactor.Container, and (3) proton.utils.BlockingConnection classes in Apache Qpid Proton before 0.12.1 improperly use an unencrypted connection for an amqps URI scheme when SSL support is unavailable, which might allow man-in-the-middle attackers to obtain sensitive information or modify data via unspecified vectors.
The (1) proton.reactor.Connector, (2) proton.reactor.Container, and (3 ...
Moderate severity vulnerability that affects org.apache.qpid:proton-j
EPSS
4.3 Medium
CVSS2