Apache Qpid Cluster Broker Authentication Security Bypass
by Carol~
- 5/1/12 11:02 AM
In Reply to: VULNERABILITIES / FIXES - May 01, 2012 by Carol~
Apache Qpid Cluster Broker Authentication Security Bypass Security Issue
Release Date : 2012-05-01
Criticality level : Moderately critical
Ipact : Security Bypass
Where : From local network
Solution Status : Vendor Workaround
Software: Apache Qpid 0.x
Description:
A security issue has been reported in Apache Qpid, which can be exploited by malicious people to bypass certain security restrictions.
The security issue is caused due to the application not verifying the password or SASL credentials when joining a cluster using a cluster-username, which can be exploited to gain unauthorised access to the cluster via a malicious broker.
Successful exploitation requires the knowledge of a valid cluster-username.
The security issue is reported in version 0.12. Other versions may also be affected.
Solution:
Fixed in the SVN repository.
Provided and/or discovered by:
Reported in a Red Hat bug report.
Original Advisory:
Qpid:
https://issues.apache.org/jira/browse/QPID-3652
https://reviews.apache.org/r/2988/diff/
Red Hat Bug#747078:
https://bugzilla.redhat.com/show_bug.cgi?id=747078
http://secunia.com/advisories/49000/

Moderator
CNET Staff
Samsung Staff
Dell Staff