The python-qpid client (common/rpc/impl_qpid.py) in OpenStack Oslo before 2013.2 does not enforce SSL connections when qpid_protocol is set to ssl, which allows remote attackers to obtain sensitive information by sniffing the network.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Oslo | Openstack | * | 2013 (including) |
Openstack | Redhat | 3.0 (including) | 3.0 (including) |
OpenStack 3 for RHEL 6 | RedHat | openstack-cinder-0:2013.1.5-2.el6ost | * |
OpenStack 3 for RHEL 6 | RedHat | openstack-glance-0:2013.1.5-1.el6ost | * |
OpenStack 3 for RHEL 6 | RedHat | openstack-quantum-0:2013.1.5-1.el6ost | * |
OpenStack 3 for RHEL 6 | RedHat | qemu-kvm-rhev-2:0.12.1.2-2.415.el6_5.6 | * |
OpenStack 3 for RHEL 6 | RedHat | openstack-nova-0:2013.1.4-4.el6ost | * |
Cinder | Ubuntu | quantal | * |
Nova | Ubuntu | precise | * |
Nova | Ubuntu | quantal | * |
Nova | Ubuntu | upstream | * |
Quantum | Ubuntu | quantal | * |