QID 981115
QID 981115: Java (maven) Security Update for org.apache.qpid:proton-j (GHSA-f5cf-f7px-xpmh)
The (1) proton.reactor.Connector, (2) proton.reactor.Container, and (3) proton.utils.BlockingConnection classes in Apache Qpid Proton before 0.12.1 improperly use an unencrypted connection for an amqps URI scheme when SSL support is unavailable, which might allow man-in-the-middle attackers to obtain sensitive information or modify data via unspecified vectors.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-f5cf-f7px-xpmh for updates pertaining to this vulnerability.
Vendor References
- GHSA-f5cf-f7px-xpmh -
github.com/advisories/GHSA-f5cf-f7px-xpmh
CVEs related to QID 981115
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-f5cf-f7px-xpmh | org.apache.qpid:proton-j |
|