CVE Vulnerabilities

CVE-2013-6470

Improper Authentication

Published: Jun 02, 2014 | Modified: Jun 03, 2014
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
5 MODERATE
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu

The default configuration in the standalone controller quickstack manifest in openstack-foreman-installer, as used in Red Hat Enterprise Linux OpenStack Platform 4.0, disables authentication for Qpid, which allows remote attackers to gain access by connecting to Qpid.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Openstack Redhat 4.0 (including) 4.0 (including)
OpenStack 4 for RHEL 6 RedHat openstack-foreman-installer-0:1.0.12-1.el6ost *

Potential Mitigations

References