CVE Vulnerabilities

CVE-2013-6491

Published: Feb 02, 2014 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
5.1 MODERATE
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The python-qpid client (common/rpc/impl_qpid.py) in OpenStack Oslo before 2013.2 does not enforce SSL connections when qpid_protocol is set to ssl, which allows remote attackers to obtain sensitive information by sniffing the network.

Affected Software

NameVendorStart VersionEnd Version
OsloOpenstack*2013 (including)
OpenstackRedhat3.0 (including)3.0 (including)
OpenStack 3 for RHEL 6RedHatopenstack-cinder-0:2013.1.5-2.el6ost*
OpenStack 3 for RHEL 6RedHatopenstack-glance-0:2013.1.5-1.el6ost*
OpenStack 3 for RHEL 6RedHatopenstack-quantum-0:2013.1.5-1.el6ost*
OpenStack 3 for RHEL 6RedHatqemu-kvm-rhev-2:0.12.1.2-2.415.el6_5.6*
OpenStack 3 for RHEL 6RedHatopenstack-nova-0:2013.1.4-4.el6ost*
CinderUbuntuquantal*
NovaUbuntuprecise*
NovaUbuntuquantal*
NovaUbuntuupstream*
QuantumUbuntuquantal*

References