Vulnerability Name: | CVE-2011-3620 (CCN-75302) | ||||||||||||||||||||||||
Assigned: | 2011-09-21 | ||||||||||||||||||||||||
Published: | 2012-04-30 | ||||||||||||||||||||||||
Updated: | 2012-08-14 | ||||||||||||||||||||||||
Summary: | Apache Qpid 0.12 does not properly verify credentials during the joining of a cluster, which allows remote attackers to obtain access to the messaging functionality and job functionality of a cluster by leveraging knowledge of a cluster-username. | ||||||||||||||||||||||||
CVSS v3 Severity: | 4.1 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N)
| ||||||||||||||||||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
3.1 Low (CCN Temporal CVSS v2 Vector: AV:A/AC:L/Au:S/C:P/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||
Vulnerability Type: | CWE-287 | ||||||||||||||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||||||||||||||
References: | Source: CCN Type: Apache Web site Qpid Source: MITRE Type: CNA CVE-2011-3620 Source: CCN Type: RHSA-2012-0528 Moderate: Red Hat Enterprise MRG Messaging 2.1 security and enhancement update Source: CCN Type: RHSA-2012-0529 Moderate: Red Hat Enterprise MRG Messaging 2.1 security and enhancement update Source: CCN Type: SA49000 Apache Qpid Cluster Broker Authentication Security Bypass Security Issue Source: SECUNIA Type: UNKNOWN 49000 Source: CCN Type: SA49001 Red Hat update for Red Hat Enterprise MRG Source: CCN Type: OSVDB ID: 81660 Apache Qpid Credential Checking Cluster Authentication Bypass Source: CCN Type: Red Hat Web site Enterprise MRG Source: CCN Type: BID-53305 Apache Qpid CVE-2011-3620 Unauthorized Access Security Bypass Vulnerability Source: SECTRACK Type: UNKNOWN 1026990 Source: CCN Type: Red Hat Bugzilla Bug 747078 CVE-2011-3620 qpid-cpp: cluster authentication ignores cluster-* settings Source: CONFIRM Type: UNKNOWN https://bugzilla.redhat.com/show_bug.cgi?id=747078 Source: XF Type: UNKNOWN apache-qpid-sasl-sec-bypass(75302) Source: CONFIRM Type: UNKNOWN https://issues.apache.org/jira/browse/QPID-3652 Source: CONFIRM Type: UNKNOWN https://reviews.apache.org/r/2988/ | ||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
BACK |