[MAVEN:GHSA-5H29-QQ92-WJ7F] Cleartext Transmission of Sensitive Information in Apache MINA

Severity High
Affected Packages 2
Fixed Packages 2
CVEs 1

Handling of the close_notify SSL/TLS message does not lead to a connection closure, leading the server to retain the socket opened and to have the client potentially receive clear text messages afterward. Mitigation: 2.0.20 users should migrate to 2.0.21, 2.1.0 users should migrate to 2.1.1. This issue affects: Apache MINA.

ID
MAVEN:GHSA-5H29-QQ92-WJ7F
Severity
high
URL
https://github.com/advisories/GHSA-5h29-qq92-wj7f
Published
2022-05-24T16:57:28
(2 years ago)
Modified
2023-01-27T05:02:38
(20 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.apache.mina/mina-core org.apache.mina mina-core = 2.1.0
Fixed pkg:maven/org.apache.mina/mina-core org.apache.mina mina-core = 2.1.1
Affected pkg:maven/org.apache.mina/mina-core org.apache.mina mina-core <= 2.0.20
Fixed pkg:maven/org.apache.mina/mina-core org.apache.mina mina-core = 2.0.21
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...