Cleartext Transmission of Sensitive Information in Apache MINA
High severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Package
Affected versions
<= 2.0.20
= 2.1.0
Patched versions
2.0.21
2.1.1
Description
Published by the National Vulnerability Database
Oct 1, 2019
Published to the GitHub Advisory Database
May 24, 2022
Reviewed
Jun 29, 2022
Last updated
Jan 27, 2023
Handling of the close_notify SSL/TLS message does not lead to a connection closure, leading the server to retain the socket opened and to have the client potentially receive clear text messages afterward. Mitigation: 2.0.20 users should migrate to 2.0.21, 2.1.0 users should migrate to 2.1.1. This issue affects: Apache MINA.
References