/
DirectorySecurity Advisories
Sign In
Security Advisories

CGA-vvxf-536v-4qjh

Published

Last updated

https://images.chainguard.dev/security/CGA-vvxf-536v-4qjh
Package

hadoop-fips-3.3.6

Repository

Chainguard

Latest Update
Pending upstream fix
Aliases
  • CVE-2019-0231
  • GHSA-5h29-qq92-wj7f

Severity

Unknown

Summary

Cleartext Transmission of Sensitive Information in Apache MINA

Description

Handling of the close_notify SSL/TLS message does not lead to a connection closure, leading the server to retain the socket opened and to have the client potentially receive clear text messages afterward. Mitigation: 2.0.20 users should migrate to 2.0.21, 2.1.0 users should migrate to 2.1.1. This issue affects: Apache MINA.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Products

Chainguard ContainersChainguard LibrariesChainguard VMs