Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-3620

Опубликовано: 30 апр. 2012
Источник: redhat
CVSS2: 5.8

Описание

Apache Qpid 0.12 does not properly verify credentials during the joining of a cluster, which allows remote attackers to obtain access to the messaging functionality and job functionality of a cluster by leveraging knowledge of a cluster-username.

Отчет

This flaw only affects the clustered implementation in qpid-cpp (qpidd-cpp-server-cluster) which is only available in Red Hat Enterprise MRG. The qpid-cpp-server as provided with Red Hat Enterprise Linux 6 does not include this functionality, and is thus not affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6mingw32-qpid-cppNot affected
Red Hat Enterprise Linux 6qpid-cppNot affected
Red Hat Enterprise MRG 1qpid-cppWill not fix
MRG for RHEL-5 v. 2condorFixedRHSA-2012:052930.04.2012
MRG for RHEL-5 v. 2python-qpidFixedRHSA-2012:052930.04.2012
MRG for RHEL-5 v. 2qpid-cpp-mrgFixedRHSA-2012:052930.04.2012
MRG for RHEL-5 v. 2qpid-javaFixedRHSA-2012:052930.04.2012
MRG for RHEL-5 v. 2qpid-jcaFixedRHSA-2012:052930.04.2012
MRG for RHEL-5 v. 2qpid-qmfFixedRHSA-2012:052930.04.2012
MRG for RHEL-5 v. 2qpid-testsFixedRHSA-2012:052930.04.2012

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=747078qpid-cpp: cluster authentication ignores cluster-* settings

5.8 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 14 лет назад

Apache Qpid 0.12 does not properly verify credentials during the joining of a cluster, which allows remote attackers to obtain access to the messaging functionality and job functionality of a cluster by leveraging knowledge of a cluster-username.

nvd
почти 14 лет назад

Apache Qpid 0.12 does not properly verify credentials during the joining of a cluster, which allows remote attackers to obtain access to the messaging functionality and job functionality of a cluster by leveraging knowledge of a cluster-username.

debian
почти 14 лет назад

Apache Qpid 0.12 does not properly verify credentials during the joini ...

github
больше 3 лет назад

Apache Qpid 0.12 does not properly verify credentials during the joining of a cluster, which allows remote attackers to obtain access to the messaging functionality and job functionality of a cluster by leveraging knowledge of a cluster-username.

5.8 Medium

CVSS2