CVE-2016-2166
Last modified
CVE-2016-2166 is a vulnerability of currently unknown severity. The (1) proton.reactor.Connector, (2) proton.reactor.Container, and (3) proton.utils.BlockingConnection classes in Apache Qpid Proton before 0.12.1 improperly use an unencrypted connection for an amqps URI scheme when SSL support is unavailable, which might allow man-in-the-middle attackers to obtain sensitive information or modify data via unspecified vectors.. EPSS estimates a 4.27% chance of exploitation in the next 30 days.
Description
The (1) proton.reactor.Connector, (2) proton.reactor.Container, and (3) proton.utils.BlockingConnection classes in Apache Qpid Proton before 0.12.1 improperly use an unencrypted connection for an amqps URI scheme when SSL support is unavailable, which might allow man-in-the-middle attackers to obtain sensitive information or modify data via unspecified vectors.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Qpid Proton | <= 0.12.0 |
| Fedoraproject | Fedora | 23 |
References
- http://lists.fedoraproject.org/pipermail/package-announce/2016-April/182414.htmlThird Party Advisory
- http://qpid.apache.org/releases/qpid-proton-0.12.1/release-notes.htmlPatch, Vendor Advisory
- https://issues.apache.org/jira/browse/PROTON-1157Issue Tracking
- http://lists.fedoraproject.org/pipermail/package-announce/2016-April/182414.htmlThird Party Advisory
- http://qpid.apache.org/releases/qpid-proton-0.12.1/release-notes.htmlPatch, Vendor Advisory
- https://issues.apache.org/jira/browse/PROTON-1157Issue Tracking
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-2166?
How severe is CVE-2016-2166?
How do I fix CVE-2016-2166?
Are you affected by CVE-2016-2166?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
