GHSA-5h29-qq92-wj7f
Dashboard / Vulnerabilities / GHSA-5h29-qq92-wj7f
Summary: Cleartext Transmission of Sensitive Information in Apache MINA
Details: Handling of the close_notify SSL/TLS message does not lead to a connection closure, leading the server to retain the socket opened and to have the client potentially receive clear text messages afterward. Mitigation: 2.0.20 users should migrate to 2.0.21, 2.1.0 users should migrate to 2.1.1. This issue affects: Apache MINA.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-0231, http://mina.apache.org/mina-project/index.html#mina-211-mina-2021-released-posted-on-april-14-2019
Affected packages
Package
Name: org.apache.mina:mina-core
Purl: pkg:maven/org.apache.mina/mina-core
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -2.0.21
Affected versions
1.0.0
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
