{ "CVE_data_meta": { "ASSIGNER": "security@apache.org", "DATE_PUBLIC": "27/9/2019", "ID": "CVE-2019-0231", "STATE": "PUBLIC", "TITLE": "Apache MINA SSLFilter security Issue" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "Apache MINA ", "version": { "version_data": [ { "version_name": "Apache MINA 2.1", "version_value": "2.1.0" }, { "version_name": "Apache MINA 2.0", "version_value": "2.0.21" } ] } } ] }, "vendor_name": "Apache Software Foundation" } ] } }, "credit": [ { "lang": "eng", "value": "This issue was discovered and reported by Oleksii Osypov." } ], "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "Handling of the close_notify SSL/TLS message does not lead to a connection closure, leading the server to retain the socket opened and to have the client potentially receive clear text messages afterward. Mitigation: 2.0.20 users should migrate to 2.0.21, 2.1.0 users should migrate to 2.1.1. This issue affects: Apache MINA." } ] }, "generator": { "engine": "Vulnogram 0.0.8" }, "impact": {}, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "SSLFilter security Issue" } ] } ] }, "references": { "reference_data": [ { "refsource": "MISC", "url": "http://mina.apache.org/mina-project/index.html#mina-211-mina-2021-released-posted-on-april-14-2019", "name": "http://mina.apache.org/mina-project/index.html#mina-211-mina-2021-released-posted-on-april-14-2019" } ] }, "source": { "discovery": "UNKNOWN" } }