CVE-2019-0231: Apache MINA SSLFilter security Issue
Handling of the closenotify SSL/TLS message does not lead to a connection closure, leading the server to retain the socket opened and to have the client potentially receive clear text messages afterward. Mitigation: 2.0.20 users should migrate to 2.0.21, 2.1.0 users should migrate to 2.1.1. This issue affects: Apache MINA.
Other sources
Handling of the closenotify SSL/TLS message does not lead to a connection closure, leading the server to retain the socket opened and to have the client potentially receive clear-text messages which were supposed to be encrypted.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-0231?
CVE-2019-0231 is a vulnerability in the handling of the close_notify SSL/TLS message that does not lead to a connection closure, potentially allowing the client to receive clear text messages afterward.
What is the severity of CVE-2019-0231?
The severity of CVE-2019-0231 is high, with a severity value of 7.5.
How does CVE-2019-0231 affect Apache MINA?
CVE-2019-0231 affects Apache MINA versions 2.0.20 and 2.1.1, with users of these versions advised to migrate to 2.0.21 and 2.1.1 respectively.
What is the mitigation for CVE-2019-0231?
The mitigation for CVE-2019-0231 is for 2.0.20 users to migrate to 2.0.21, and for 2.1.0 users to migrate to 2.1.1.
Where can I find more information about CVE-2019-0231?
You can find more information about CVE-2019-0231 at the following references: [1] [2] [3].