Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-0223

Опубликовано: 27 янв. 2015
Источник: redhat
CVSS2: 5.8
EPSS Низкий

Описание

Unspecified vulnerability in Apache Qpid 0.30 and earlier allows remote attackers to bypass access restrictions on qpidd via unknown vectors, related to 0-10 connection handling.

It was discovered that the Qpid daemon (qpidd) did not restrict access to anonymous users when the ANONYMOUS mechanism was disallowed.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6qpid-cppWill not fix
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7qpid-cppWill not fix
MRG for RHEL-5 v. 2qpid-cpp-mrgFixedRHSA-2015:066209.03.2015
MRG for RHEL-6 v.3python-qpidFixedRHSA-2015:070719.03.2015
MRG for RHEL-6 v.3qpid-cppFixedRHSA-2015:070719.03.2015
MRG for RHEL-6 v.3qpid-qmfFixedRHSA-2015:070719.03.2015
MRG Messaging v.3 for RHEL-7libdbFixedRHSA-2015:070819.03.2015
MRG Messaging v.3 for RHEL-7python-qpidFixedRHSA-2015:070819.03.2015
MRG Messaging v.3 for RHEL-7qpid-cppFixedRHSA-2015:070819.03.2015
MRG Messaging v.3 for RHEL-7qpid-qmfFixedRHSA-2015:070819.03.2015

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1186308qpid-cpp: anonymous access to qpidd cannot be prevented

EPSS

Процентиль: 84%
0.02275
Низкий

5.8 Medium

CVSS2

Связанные уязвимости

ubuntu
около 11 лет назад

Unspecified vulnerability in Apache Qpid 0.30 and earlier allows remote attackers to bypass access restrictions on qpidd via unknown vectors, related to 0-10 connection handling.

nvd
около 11 лет назад

Unspecified vulnerability in Apache Qpid 0.30 and earlier allows remote attackers to bypass access restrictions on qpidd via unknown vectors, related to 0-10 connection handling.

debian
около 11 лет назад

Unspecified vulnerability in Apache Qpid 0.30 and earlier allows remot ...

github
больше 3 лет назад

Unspecified vulnerability in Apache Qpid 0.30 and earlier allows remote attackers to bypass access restrictions on qpidd via unknown vectors, related to 0-10 connection handling.

EPSS

Процентиль: 84%
0.02275
Низкий

5.8 Medium

CVSS2