CVE-2019-0223 Affecting qpid-proton package, versions <0.22.0-1


Severity

Recommended
0.0
high
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
6.2% (93rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-ECHOLATEST-QPIDPROTON-18533402
  • published5 Aug 2026
  • disclosed23 Apr 2019

Introduced: 23 Apr 2019

CVE-2019-0223  (opens in a new tab)

How to fix?

Upgrade Echo:latest qpid-proton to version 0.22.0-1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream qpid-proton package and not the qpid-proton package as distributed by Echo. See How to fix? for Echo:latest relevant fixed versions and status.

While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0.9 to 0.27.0 (C library and its language bindings) can connect to a peer anonymously using TLS even when configured to verify the peer certificate while used with OpenSSL versions before 1.1.0. This means that an undetected man in the middle attack could be constructed if an attacker can arrange to intercept TLS traffic.

References

CVSS Base Scores

version 3.1