CVE-2019-0231 is a vulnerability in Apache Mina
Published on October 1, 2019
Apache MINA SSLFilter security Issue
Handling of the close_notify SSL/TLS message does not lead to a connection closure, leading the server to retain the socket opened and to have the client potentially receive clear text messages afterward. Mitigation: 2.0.20 users should migrate to 2.0.21, 2.1.0 users should migrate to 2.1.1. This issue affects: Apache MINA.
Products Associated with CVE-2019-0231
Want to know whenever a new CVE is published for Apache Mina? stack.watch will email you.
Affected Versions
Apache Software Foundation Apache MINA:- Version Apache MINA 2.1 2.1.0 is affected.
- Version Apache MINA 2.0 2.0.21 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.