Search CVE reports


Toggle filters

1 – 4 of 4 results


CVE-2019-0223

Medium priority
Needs evaluation

While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0.9 to 0.27.0 (C library and its language bindings) can connect to a peer anonymously using TLS *even when configured to...

1 affected package

qpid-proton

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qpid-proton Not affected Not affected Not affected Needs evaluation
Show less packages

CVE-2018-17187

Medium priority
Needs evaluation

The Apache Qpid Proton-J transport includes an optional wrapper layer to perform TLS, enabled by use of the ‘transport.ssl(...)’ methods. Unless a verification mode was explicitly configured, client and server modes previously...

1 affected package

qpid-proton

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qpid-proton Not affected Not affected Not affected Needs evaluation
Show less packages

CVE-2016-4467

Medium priority
Not affected

The C client and C-based client bindings in the Apache Qpid Proton library before 0.13.1 on Windows do not properly verify that the server hostname matches a domain name in the subject’s Common Name (CN) or subjectAltName field of...

1 affected package

qpid-proton

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qpid-proton
Show less packages

CVE-2016-2166

Medium priority
Vulnerable

The (1) proton.reactor.Connector, (2) proton.reactor.Container, and (3) proton.utils.BlockingConnection classes in Apache Qpid Proton before 0.12.1 improperly use an unencrypted connection for an amqps URI scheme when SSL support...

1 affected package

qpid-proton

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qpid-proton Not affected Not affected Not affected Not affected
Show less packages