PT-2013-1671 · Apache · Apache Qpid

Charles E. Rolke

·

Published

2013-03-12

·

Updated

2022-05-17

·

CVE-2012-4446

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Apache Qpid versions 0.20 and earlier
Description The issue concerns the default configuration of Apache Qpid when the federation tag attribute is enabled. In this setup, the software accepts AMQP connections without verifying the source user ID. This allows remote attackers to bypass authentication, potentially leading to unauthorized access.
Recommendations For Apache Qpid versions 0.20 and earlier, consider disabling the federation tag attribute until a proper fix is applied to prevent unauthorized access. Additionally, restrict access to AMQP connections to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-4446
GHSA-MRGH-6X42-X6XF
RHSA-2013:0561
RHSA-2013:0562

Affected Products

Apache Qpid