CVE Vulnerabilities

CVE-2013-6491

Published: Feb 02, 2014 | Modified: Jun 21, 2014
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
5.1 MODERATE
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

The python-qpid client (common/rpc/impl_qpid.py) in OpenStack Oslo before 2013.2 does not enforce SSL connections when qpid_protocol is set to ssl, which allows remote attackers to obtain sensitive information by sniffing the network.

Affected Software

Name Vendor Start Version End Version
Oslo Openstack * 2013 (including)
Openstack Redhat 3.0 (including) 3.0 (including)
OpenStack 3 for RHEL 6 RedHat openstack-cinder-0:2013.1.5-2.el6ost *
OpenStack 3 for RHEL 6 RedHat openstack-glance-0:2013.1.5-1.el6ost *
OpenStack 3 for RHEL 6 RedHat openstack-quantum-0:2013.1.5-1.el6ost *
OpenStack 3 for RHEL 6 RedHat qemu-kvm-rhev-2:0.12.1.2-2.415.el6_5.6 *
OpenStack 3 for RHEL 6 RedHat openstack-nova-0:2013.1.4-4.el6ost *
Cinder Ubuntu quantal *
Nova Ubuntu precise *
Nova Ubuntu quantal *
Nova Ubuntu upstream *
Quantum Ubuntu quantal *

References