CVE-2012-4446

CVSS v2.0 6.8 (Medium)
68% Progress
EPSS 0.32 % (71th)
0.32% Progress
Affected Products 1
Advisories 1

The default configuration for Apache Qpid 0.20 and earlier, when the federation_tag attribute is enabled, accepts AMQP connections without checking the source user ID, which allows remote attackers to bypass authentication and have other unspecified impact via an AMQP request.

Weaknesses
CWE-287
Improper Authentication
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2013-03-14 03:10:22
(11 years ago)
Updated Date
2013-03-19 04:00:00
(11 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Apache Qpid 0.20 and prior versions cpe:2.3:a:apache:qpid <= 0.20
  Apache Qpid 0.5 cpe:2.3:a:apache:qpid:0.5
  Apache Qpid 0.6 cpe:2.3:a:apache:qpid:0.6
  Apache Qpid 0.7 cpe:2.3:a:apache:qpid:0.7
  Apache Qpid 0.8 cpe:2.3:a:apache:qpid:0.8
  Apache Qpid 0.9 cpe:2.3:a:apache:qpid:0.9
  Apache Qpid 0.10 cpe:2.3:a:apache:qpid:0.10
  Apache Qpid 0.11 cpe:2.3:a:apache:qpid:0.11
  Apache Qpid 0.12 cpe:2.3:a:apache:qpid:0.12
  Apache Qpid 0.13 cpe:2.3:a:apache:qpid:0.13
  Apache Qpid 0.14 cpe:2.3:a:apache:qpid:0.14
  Apache Qpid 0.15 cpe:2.3:a:apache:qpid:0.15
  Apache Qpid 0.16 cpe:2.3:a:apache:qpid:0.16
  Apache Qpid 0.17 cpe:2.3:a:apache:qpid:0.17
  Apache Qpid 0.18 cpe:2.3:a:apache:qpid:0.18
  Apache Qpid 0.19 cpe:2.3:a:apache:qpid:0.19
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...