PT-2012-1003 · Apache · Apache Qpid

Paul Colby

·

Published

2012-06-22

·

Updated

2022-05-17

·

CVE-2012-3467

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Apache QPID versions 0.14, 0.16, and earlier
Description The issue is related to an error in the authentication mechanism when handling AMQP client shadow connections, allowing remote attackers to bypass authentication. This could potentially enable an attacker to impersonate a legitimate user by sending a specially crafted request.
Recommendations For Apache QPID versions 0.14, 0.16, and earlier, consider disabling the NullAuthenticator mechanism as a temporary workaround until a patch is available. Restrict access to the AMQP broker to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2014-00013
CVE-2012-3467
GHSA-PHW8-FW9G-V3XC
RHSA-2012:1277
RHSA-2012:1279

Affected Products

Apache Qpid