CVE-2019-0231
Handling of the close_notify SSL/TLS message does not lead to a connection closure, leading the server to retain the socket opened and to have the client potentially receive clear text messages afterward.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.20%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Handling of the close_notify SSL/TLS message does not lead to a connection closure, leading the server to retain the socket opened and to have the client potentially receive clear text messages afterward. Mitigation: 2.0.20 users should migrate to 2.0.21, 2.1.0 users should migrate to 2.1.1. This issue affects: Apache MINA.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 2.20% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-319
- Affected
- apache/mina
- Source
- security@apache.org
References
- http://mina.apache.org/mina-project/index.html#mina-211-mina-2021-released-posted-on-april-14-2019Release Notes, Vendor Advisory
- http://mina.apache.org/mina-project/index.html#mina-211-mina-2021-released-posted-on-april-14-2019Release Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.