Vulnerabilities (CVE)

Filtered by vendor Apache Subscribe
Filtered by product Qpid
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-0223 2 Apache, Redhat 3 Qpid, Jboss Amq Clients 2, Linux 2021-07-21 4.0 MEDIUM 7.4 HIGH
While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0.9 to 0.27.0 (C library and its language bindings) can connect to a peer anonymously using TLS *even when configured to verify the peer certificate* while used with OpenSSL versions before 1.1.0. This means that an undetected man in the middle attack could be constructed if an attacker can arrange to intercept TLS traffic.
CVE-2015-0224 1 Apache 1 Qpid 2018-10-09 5.0 MEDIUM 7.5 HIGH
qpidd in Apache Qpid 0.30 and earlier allows remote attackers to cause a denial of service (daemon crash) via a crafted protocol sequence set. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-0203.