Vulnerability Name: | CVE-2012-3467 (CCN-77568) | ||||||||||||||||||||
Assigned: | 2012-08-09 | ||||||||||||||||||||
Published: | 2012-08-09 | ||||||||||||||||||||
Updated: | 2017-08-29 | ||||||||||||||||||||
Summary: | Apache QPID 0.14, 0.16, and earlier uses a NullAuthenticator mechanism to authenticate catch-up shadow connections to AMQP brokers, which allows remote attackers to bypass authentication. | ||||||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||||||||||||||
Vulnerability Type: | CWE-287 | ||||||||||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||||||||||
References: | Source: CCN Type: Apache Web site Qpid Source: MITRE Type: CNA CVE-2012-3467 Source: CCN Type: Apache Qpid SVN Repository Apache Qpid Source: CCN Type: RHSA-2012-1277 Moderate: Red Hat Enterprise MRG Messaging 2.2 update Source: REDHAT Type: UNKNOWN RHSA-2012:1277 Source: CCN Type: RHSA-2012-1279 Moderate: Red Hat Enterprise MRG Messaging 2.2 update Source: REDHAT Type: UNKNOWN RHSA-2012:1279 Source: CCN Type: SA50186 Apache Qpid AMQP Client Shadow Connection Authentication Bypass Vulnerability Source: SECUNIA Type: Vendor Advisory 50186 Source: SECUNIA Type: UNKNOWN 50698 Source: CONFIRM Type: UNKNOWN http://svn.apache.org/viewvc?view=revision&revision=1352992 Source: CCN Type: oss-security: Vincent Danen | 9 Aug CVE-2012-3467: Unauthorized access (authentication bypass) from client to broker due to use of NullAuthenticator in shadow connections Source: MLIST Type: UNKNOWN [oss-security] 20120809 CVE-2012-3467: Unauthorized access (authentication bypass) from client to broker due to use of NullAuthenticator in shadow connections Source: CCN Type: OSVDB ID: 84562 Apache Qpid Broker Authentication Mechanism AMQP Client Shadow Connection NullAuthenticator Request Parsing Authentication Bypass Source: BID Type: UNKNOWN 54954 Source: CCN Type: BID-54954 Apache QPID NullAuthenticator Authentication Bypass Vulnerability Source: MISC Type: UNKNOWN https://bugzilla.redhat.com/show_bug.cgi?id=836276 Source: XF Type: UNKNOWN apache-qpid-broker-sec-bypass(77568) Source: XF Type: UNKNOWN apache-qpid-broker-sec-bypass(77568) Source: CONFIRM Type: UNKNOWN https://issues.apache.org/jira/browse/QPID-3849 | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |