Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Charles E. Rolke

#40081de 53,638
6.8CVSS total
Vulnerabilidades · 1
PT-2013-1671
6.8
2013-03-12
Apache · Apache Qpid · CVE-2012-4446
**Name of the Vulnerable Software and Affected Versions** Apache Qpid versions 0.20 and earlier **Description** The issue concerns the default configuration of Apache Qpid when the federation tag attribute is enabled. In this setup, the software accepts AMQP connections without verifying the source user ID. This allows remote attackers to bypass authentication, potentially leading to unauthorized access. **Recommendations** For Apache Qpid versions 0.20 and earlier, consider disabling the federation tag attribute until a proper fix is applied to prevent unauthorized access. Additionally, restrict access to AMQP connections to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.