CVE Vulnerabilities

CVE-2012-4446

Improper Authentication

Published: Mar 14, 2013 | Modified: Mar 19, 2013
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The default configuration for Apache Qpid 0.20 and earlier, when the federation_tag attribute is enabled, accepts AMQP connections without checking the source user ID, which allows remote attackers to bypass authentication and have other unspecified impact via an AMQP request.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Qpid Apache * 0.20 (including)
Qpid Apache 0.5 (including) 0.5 (including)
Qpid Apache 0.6 (including) 0.6 (including)
Qpid Apache 0.7 (including) 0.7 (including)
Qpid Apache 0.8 (including) 0.8 (including)
Qpid Apache 0.9 (including) 0.9 (including)
Qpid Apache 0.10 (including) 0.10 (including)
Qpid Apache 0.11 (including) 0.11 (including)
Qpid Apache 0.12 (including) 0.12 (including)
Qpid Apache 0.13 (including) 0.13 (including)
Qpid Apache 0.14 (including) 0.14 (including)
Qpid Apache 0.15 (including) 0.15 (including)
Qpid Apache 0.16 (including) 0.16 (including)
Qpid Apache 0.17 (including) 0.17 (including)
Qpid Apache 0.18 (including) 0.18 (including)
Qpid Apache 0.19 (including) 0.19 (including)

Potential Mitigations

References