← Back

CVE-2016-2166

nvd nist
Published: Apr 12, 2016Modified: May 6, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N
Exploitability: 2.2 / Impact: 4.2
Source: NVD

Description

The (1) proton.reactor.Connector, (2) proton.reactor.Container, and (3) proton.utils.BlockingConnection classes in Apache Qpid Proton before 0.12.1 improperly use an unencrypted connection for an amqps URI scheme when SSL support is unavailable, which might allow man-in-the-middle attackers to obtain sensitive information or modify data via unspecified vectors.

Affected (2)

1 product
Qpid Proton
1 product
Fedora
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 0.12.0
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 23

References (14)

Source: secalert@redhat.com
PatchVendor Advisory
Source: secalert@redhat.com
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking

Timeline

No history available yet.