#VU15933 Man-in-the-middle attack in Apache Qpid Proton-J - CVE-2018-17187
Published: November 16, 2018 / Updated: November 17, 2018
Apache Qpid Proton-J
Apache Foundation
Description
The vulnerability allows a remote attacker to man-in-the-middle (MITM) attack on the target system.
The vulnerability exists due to the transport.ssl(...) methods of the affected software are missing Transport Layer Security (TLS) hostname-verification functionality. A remote unauthenticated attacker can execute a man-in-the-middle attack to bypass hostname-based TLS verification controls and gain unauthorized access to the targeted system.