CVE Vulnerabilities

CVE-2019-0223

Published: Apr 23, 2019 | Modified: Nov 21, 2024
CVSS 3.x
7.4
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
7.4 IMPORTANT
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0.9 to 0.27.0 (C library and its language bindings) can connect to a peer anonymously using TLS even when configured to verify the peer certificate while used with OpenSSL versions before 1.1.0. This means that an undetected man in the middle attack could be constructed if an attacker can arrange to intercept TLS traffic.

Affected Software

NameVendorStart VersionEnd Version
QpidApache0.9 (including)0.27.0 (including)
AMQ Clients 2.y for RHEL 6RedHatqpid-proton-0:0.27.0-3.el6*
AMQ Clients 2.y for RHEL 7RedHatqpid-proton-0:0.27.0-3.el7*
CloudForms Management Engine 5.11RedHatansible-runner-0:1.3.4-2.el8ar*
CloudForms Management Engine 5.11RedHatansible-tower-0:3.5.2-1.el8at*
CloudForms Management Engine 5.11RedHatcfme-0:5.11.0.28-1.el8cf*
CloudForms Management Engine 5.11RedHatcfme-amazon-smartstate-0:5.11.0.28-1.el8cf*
CloudForms Management Engine 5.11RedHatcfme-appliance-0:5.11.0.28-1.el8cf*
CloudForms Management Engine 5.11RedHatcfme-gemset-0:5.11.0.28-1.el8cf*
CloudForms Management Engine 5.11RedHatovirt-ansible-cluster-upgrade-0:1.1.13-1.el8ev*
CloudForms Management Engine 5.11RedHatovirt-ansible-disaster-recovery-0:1.2.0-1.el8ev*
CloudForms Management Engine 5.11RedHatovirt-ansible-engine-setup-0:1.1.9-1.el8ev*
CloudForms Management Engine 5.11RedHatovirt-ansible-hosted-engine-setup-0:1.0.26-1.el8ev*
CloudForms Management Engine 5.11RedHatovirt-ansible-image-template-0:1.1.11-1.el8ev*
CloudForms Management Engine 5.11RedHatovirt-ansible-infra-0:1.1.12-1.el8ev*
CloudForms Management Engine 5.11RedHatovirt-ansible-manageiq-0:1.1.14-1.el8ev*
CloudForms Management Engine 5.11RedHatovirt-ansible-repositories-0:1.1.5-1.el8ev*
CloudForms Management Engine 5.11RedHatovirt-ansible-roles-0:1.1.7-2.el8ev*
CloudForms Management Engine 5.11RedHatovirt-ansible-shutdown-env-0:1.0.3-1.el8ev*
CloudForms Management Engine 5.11RedHatovirt-ansible-vm-infra-0:1.1.19-1.el8ev*
CloudForms Management Engine 5.11RedHatprince-0:12.4-1.el8cf*
CloudForms Management Engine 5.11RedHatpython3-ovirt-engine-sdk4-0:4.3.2-1.el8ev*
CloudForms Management Engine 5.11RedHatpython-bambou-0:3.0.1-2.el8cf*
CloudForms Management Engine 5.11RedHatpython-colorama-0:0.4.1-1.el8ost*
CloudForms Management Engine 5.11RedHatpython-daemon-0:2.1.2-9.el8ar*
CloudForms Management Engine 5.11RedHatpython-funcsigs-0:1.0.2-3.el8ost*
CloudForms Management Engine 5.11RedHatpython-future-0:0.16.0-1.el8cf*
CloudForms Management Engine 5.11RedHatpython-lockfile-1:0.11.0-8.el8ar*
CloudForms Management Engine 5.11RedHatpython-mock-0:2.0.0-11.el8ost*
CloudForms Management Engine 5.11RedHatpython-pbr-0:5.1.2-2.el8ost*
CloudForms Management Engine 5.11RedHatpython-pexpect-0:4.6-2.el8ar*
CloudForms Management Engine 5.11RedHatpython-psutil-0:5.4.3-5.el8ar*
CloudForms Management Engine 5.11RedHatpython-pylxca-0:2.1.1-2.el8cf*
CloudForms Management Engine 5.11RedHatpython-requests-toolbelt-0:0.8.0-2.el8cf*
CloudForms Management Engine 5.11RedHatpython-tabulate-0:0.8.2-1.el8cf*
CloudForms Management Engine 5.11RedHatpython-vspk-0:5.3.2-2.el8cf*
CloudForms Management Engine 5.11RedHatqpid-proton-0:0.28.0-1.el8*
CloudForms Management Engine 5.11RedHatrepmgr10-0:4.0.6-3.el8cf*
CloudForms Management Engine 5.11RedHatrubygem-bcrypt-0:3.1.13-1.el8cf*
CloudForms Management Engine 5.11RedHatrubygem-byebug-0:11.0.1-1.el8cf*
CloudForms Management Engine 5.11RedHatrubygem-escape_utils-0:1.2.1-1.el8cf*
CloudForms Management Engine 5.11RedHatrubygem-ffi-0:1.9.25-1.el8cf*
CloudForms Management Engine 5.11RedHatrubygem-hamlit-0:2.8.10-1.el8cf*
CloudForms Management Engine 5.11RedHatrubygem-http_parser.rb-0:0.6.0-1.el8cf*
CloudForms Management Engine 5.11RedHatrubygem-linux_block_device-0:0.2.1-1.el8cf*
CloudForms Management Engine 5.11RedHatrubygem-memory_buffer-0:0.1.0-2.el8cf*
CloudForms Management Engine 5.11RedHatrubygem-nio4r-0:2.4.0-1.el8cf*
CloudForms Management Engine 5.11RedHatrubygem-nokogiri-0:1.8.5-1.el8cf*
CloudForms Management Engine 5.11RedHatrubygem-ovirt-engine-sdk4-0:4.3.0-1.el8cf*
CloudForms Management Engine 5.11RedHatrubygem-puma-0:3.7.1-1.el8cf*
CloudForms Management Engine 5.11RedHatrubygem-qpid_proton-0:0.26.0-1.el8cf*
CloudForms Management Engine 5.11RedHatrubygem-rugged-0:0.28.2-1.el8cf*
CloudForms Management Engine 5.11RedHatrubygem-sassc-0:2.0.1-1.el8cf*
CloudForms Management Engine 5.11RedHatrubygem-sqlite3-0:1.3.13-2.el8cf*
CloudForms Management Engine 5.11RedHatrubygem-surro-gate-0:1.0.5-1.el8cf*
CloudForms Management Engine 5.11RedHatrubygem-unf_ext-0:0.0.7.6-1.el8cf*
CloudForms Management Engine 5.11RedHatrubygem-websocket-driver-0:0.6.5-1.el8cf*
CloudForms Management Engine 5.11RedHatsmem-0:1.4-1.el8cf*
CloudForms Management Engine 5.11RedHatv2v-conversion-host-0:1.14.2-1.el8ev*
CloudForms Management Engine 5.11RedHatwmi-0:1.3.14-8.el8cf*
Red Hat OpenStack Platform 13.0 (Queens)RedHatjsoncpp-0:1.7.7-1.el7*
Red Hat OpenStack Platform 13.0 (Queens)RedHatqpid-proton-0:0.27.0-3.el7*
Red Hat OpenStack Platform 14.0 Operational Tools for RHEL 7RedHatqpid-proton-0:0.27.0-3.el7*
Red Hat OpenStack Platform 14.0 (Rocky)RedHatqpid-proton-0:0.27.0-3.el7*
Red Hat Satellite 6.3 for RHEL 7RedHatqpid-proton-0:0.16.0-14.el7sat*
Red Hat Satellite 6.3 for RHEL 7RedHatqpid-proton-0:0.16.0-14.el7sat*
Red Hat Satellite 6.4 for RHEL 7RedHatqpid-proton-0:0.16.0-14.el7sat*
Red Hat Satellite 6.4 for RHEL 7RedHatqpid-proton-0:0.16.0-14.el7sat*
Red Hat Satellite 6.5 for RHEL 7RedHatqpid-proton-0:0.28.0-1.el7*
Red Hat Satellite 6.5 for RHEL 7RedHatqpid-proton-0:0.28.0-1.el7*
Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUSRedHatqpid-proton-0:0.28.0-1.el7*
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7RedHatqpid-proton-0:0.28.0-1.el7*
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7RedHatqpid-proton-0:0.16.0-14.el7sat*
Satellite Tools 6.3 for RHEL 5.9.AUSRedHatqpid-proton-0:0.9-22.el5*
Satellite Tools 6.3 for RHEL 5.ELSRedHatqpid-proton-0:0.9-22.el5*
Satellite Tools 6.3 for RHEL 6RedHatqpid-proton-0:0.16.0-14.el6sat*
Satellite Tools 6.3 for RHEL 6.4.AUSRedHatqpid-proton-0:0.16.0-14.el6sat*
Satellite Tools 6.3 for RHEL 6.5.AUSRedHatqpid-proton-0:0.16.0-14.el6sat*
Satellite Tools 6.3 for RHEL 6.6.AUSRedHatqpid-proton-0:0.16.0-14.el6sat*
Satellite Tools 6.3 for RHEL 6.7.EUSRedHatqpid-proton-0:0.16.0-14.el6sat*
Satellite Tools 6.3 for RHEL 7RedHatqpid-proton-0:0.16.0-14.el7sat*
Satellite Tools 6.3 for RHEL 7.2.AUSRedHatqpid-proton-0:0.16.0-14.el7sat*
Satellite Tools 6.3 for RHEL 7.2.E4SRedHatqpid-proton-0:0.16.0-14.el7sat*
Satellite Tools 6.3 for RHEL 7.2.EUSRedHatqpid-proton-0:0.16.0-14.el7sat*
Satellite Tools 6.3 for RHEL 7.3.AUSRedHatqpid-proton-0:0.16.0-14.el7sat*
Satellite Tools 6.3 for RHEL 7.3.E4SRedHatqpid-proton-0:0.16.0-14.el7sat*
Satellite Tools 6.3 for RHEL 7.3.EUSRedHatqpid-proton-0:0.16.0-14.el7sat*
Satellite Tools 6.3 for RHEL 7.4.AUSRedHatqpid-proton-0:0.16.0-14.el7sat*
Satellite Tools 6.3 for RHEL 7.4.E4SRedHatqpid-proton-0:0.16.0-14.el7sat*
Satellite Tools 6.3 for RHEL 7.4.EUSRedHatqpid-proton-0:0.16.0-14.el7sat*
Satellite Tools 6.3 for RHEL 7.5.EUSRedHatqpid-proton-0:0.16.0-14.el7sat*
Satellite Tools 6.3 for RHEL 7.6.AUSRedHatqpid-proton-0:0.16.0-14.el7sat*
Satellite Tools 6.3 for RHEL 7.6.E4SRedHatqpid-proton-0:0.16.0-14.el7sat*
Satellite Tools 6.3 for RHEL 7.6.EUSRedHatqpid-proton-0:0.16.0-14.el7sat*
Satellite Tools 6.4 for RHEL 5.9.AUSRedHatqpid-proton-0:0.9-22.el5*
Satellite Tools 6.4 for RHEL 5.ELSRedHatqpid-proton-0:0.9-22.el5*
Satellite Tools 6.4 for RHEL 6RedHatqpid-proton-0:0.16.0-14.el6sat*
Satellite Tools 6.4 for RHEL 6.7.EUSRedHatqpid-proton-0:0.16.0-14.el6sat*
Satellite Tools 6.4 for RHEL 7RedHatqpid-proton-0:0.16.0-14.el7sat*
Satellite Tools 6.4 for RHEL 7.2.AUSRedHatqpid-proton-0:0.16.0-14.el7sat*
Satellite Tools 6.4 for RHEL 7.2.E4SRedHatqpid-proton-0:0.16.0-14.el7sat*
Satellite Tools 6.4 for RHEL 7.2.TUSRedHatqpid-proton-0:0.16.0-14.el7sat*
Satellite Tools 6.4 for RHEL 7.3.AUSRedHatqpid-proton-0:0.16.0-14.el7sat*
Satellite Tools 6.4 for RHEL 7.3.E4SRedHatqpid-proton-0:0.16.0-14.el7sat*
Satellite Tools 6.4 for RHEL 7.3.TUSRedHatqpid-proton-0:0.16.0-14.el7sat*
Satellite Tools 6.4 for RHEL 7.4.AUSRedHatqpid-proton-0:0.16.0-14.el7sat*
Satellite Tools 6.4 for RHEL 7.4.E4SRedHatqpid-proton-0:0.16.0-14.el7sat*
Satellite Tools 6.4 for RHEL 7.4.EUSRedHatqpid-proton-0:0.16.0-14.el7sat*
Satellite Tools 6.4 for RHEL 7.4.TUSRedHatqpid-proton-0:0.16.0-14.el7sat*
Satellite Tools 6.4 for RHEL 7.5.EUSRedHatqpid-proton-0:0.16.0-14.el7sat*
Satellite Tools 6.4 for RHEL 7.6.AUSRedHatqpid-proton-0:0.16.0-14.el7sat*
Satellite Tools 6.4 for RHEL 7.6.E4SRedHatqpid-proton-0:0.16.0-14.el7sat*
Satellite Tools 6.4 for RHEL 7.6.EUSRedHatqpid-proton-0:0.16.0-14.el7sat*
Satellite Tools 6.4 for RHEL 7.6.TUSRedHatqpid-proton-0:0.16.0-14.el7sat*
Satellite Tools 6.5 for RHEL 5.9.AUSRedHatqpid-proton-0:0.9-22.el5*
Satellite Tools 6.5 for RHEL 5.ELSRedHatqpid-proton-0:0.9-22.el5*
Satellite Tools 6.5 for RHEL 6RedHatqpid-proton-0:0.16.0-14.el6sat*
Satellite Tools 6.5 for RHEL 7RedHatqpid-proton-0:0.28.0-1.el7*
Satellite Tools 6.5 for RHEL 7.2.AUSRedHatqpid-proton-0:0.28.0-1.el7*
Satellite Tools 6.5 for RHEL 7.2.E4SRedHatqpid-proton-0:0.28.0-1.el7*
Satellite Tools 6.5 for RHEL 7.2.TUSRedHatqpid-proton-0:0.28.0-1.el7*
Satellite Tools 6.5 for RHEL 7.3.AUSRedHatqpid-proton-0:0.28.0-1.el7*
Satellite Tools 6.5 for RHEL 7.3.E4SRedHatqpid-proton-0:0.28.0-1.el7*
Satellite Tools 6.5 for RHEL 7.3.TUSRedHatqpid-proton-0:0.28.0-1.el7*
Satellite Tools 6.5 for RHEL 7.4.AUSRedHatqpid-proton-0:0.28.0-1.el7*
Satellite Tools 6.5 for RHEL 7.4.E4SRedHatqpid-proton-0:0.28.0-1.el7*
Satellite Tools 6.5 for RHEL 7.4.EUSRedHatqpid-proton-0:0.28.0-1.el7*
Satellite Tools 6.5 for RHEL 7.4.TUSRedHatqpid-proton-0:0.28.0-1.el7*
Satellite Tools 6.5 for RHEL 7.5.EUSRedHatqpid-proton-0:0.28.0-1.el7*
Satellite Tools 6.5 for RHEL 7.6.AUSRedHatqpid-proton-0:0.28.0-1.el7*
Satellite Tools 6.5 for RHEL 7.6.E4SRedHatqpid-proton-0:0.28.0-1.el7*
Satellite Tools 6.5 for RHEL 7.6.EUSRedHatqpid-proton-0:0.28.0-1.el7*
Satellite Tools 6.5 for RHEL 7.6.TUSRedHatqpid-proton-0:0.28.0-1.el7*
Satellite Tools 6.5 for RHEL 8RedHatqpid-proton-0:0.28.0-1.el8*
Qpid-protonUbuntubionic*
Qpid-protonUbuntucosmic*
Qpid-protonUbuntuxenial*

References