SB2018111701 - Man-in-the-middle attack in Apache Qpid Proton-J
Published: November 17, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Man-in-the-middle attack (CVE-ID: CVE-2018-17187)
The vulnerability allows a remote attacker to man-in-the-middle (MITM) attack on the target system.
The vulnerability exists due to the transport.ssl(...) methods of the affected software are missing Transport Layer Security (TLS) hostname-verification functionality. A remote unauthenticated attacker can execute a man-in-the-middle attack to bypass hostname-based TLS verification controls and gain unauthorized access to the targeted system.
Remediation
Install update from vendor's website.