CVE-2011-3620
published 2012-05-03CVE-2011-3620: Apache Qpid 0.12 does not properly verify credentials during the joining of a cluster, which allows remote attackers to obtain access to the messaging…
PriorityP343high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
5.31%
91.6th percentile
Apache Qpid 0.12 does not properly verify credentials during the joining of a cluster, which allows remote attackers to obtain access to the messaging functionality and job functionality of a cluster by leveraging knowledge of a cluster-username.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | qpid | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3j5v-8288-v25g: Apache Qpid 0
ghsa_unreviewed·2022-05-17
CVE-2011-3620 [HIGH] CWE-287 GHSA-3j5v-8288-v25g: Apache Qpid 0
Apache Qpid 0.12 does not properly verify credentials during the joining of a cluster, which allows remote attackers to obtain access to the messaging functionality and job functionality of a cluster by leveraging knowledge of a cluster-username.
Red Hat
qpid-cpp: cluster authentication ignores cluster-* settings
vendor_redhat·2012-04-30·CVSS 7.5
CVE-2011-3620 [HIGH] qpid-cpp: cluster authentication ignores cluster-* settings
qpid-cpp: cluster authentication ignores cluster-* settings
Apache Qpid 0.12 does not properly verify credentials during the joining of a cluster, which allows remote attackers to obtain access to the messaging functionality and job functionality of a cluster by leveraging knowledge of a cluster-username.
Statement: This flaw only affects the clustered implementation in qpid-cpp (qpidd-cpp-server-cluster) which is only available in Red Hat Enterprise MRG. The qpid-cpp-server as provided with Red Hat Enterprise Linux 6 does not include this functionality, and is thus not affected.
Package: mingw32-qpid-cpp (Red Hat Enterprise Linux 6) - Not affected
Package: qpid-cpp (Red Hat Enterprise Linux 6) - Not affected
Package: qpid-cpp (Red Hat Enterprise MRG 1) - Will not fix
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-3620 qpid-cpp: cluster authentication ignores cluster-* settings [fedora-all]
bugzilla·2012-04-30·CVSS 7.5
CVE-2011-3620 [HIGH] CVE-2011-3620 qpid-cpp: cluster authentication ignores cluster-* settings [fedora-all]
CVE-2011-3620 qpid-cpp: cluster authentication ignores cluster-* settings [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?typ
Bugzilla
CVE-2011-3620 qpid-cpp: cluster authentication ignores cluster-* settings
bugzilla·2011-10-18·CVSS 7.5
CVE-2011-3620 [HIGH] CVE-2011-3620 qpid-cpp: cluster authentication ignores cluster-* settings
CVE-2011-3620 qpid-cpp: cluster authentication ignores cluster-* settings
A flaw was found in qpid where it would accept any password or SASL mechanism,
provided the remote user knew a valid cluster username. This would give a
malicious remote attacker unauthorized access to the cluster where they would
be able to receive replicated messages to the cluster, be able to send any
cluster message, mark any present message as consumed, run any job on the
cluster, and also view/modify/create other users' jobs. Only cluster messages
and internal qpid/MRG configuration is accessible to the remote attacker.
Discussion:
For an attacker to successfully exploit this flaw, they would need to have physical access to the wired private interconnect LAN in which to plug in their own system. Typically, M
http://secunia.com/advisories/49000http://www.securitytracker.com/id?1026990https://bugzilla.redhat.com/show_bug.cgi?id=747078https://issues.apache.org/jira/browse/QPID-3652https://reviews.apache.org/r/2988/http://secunia.com/advisories/49000http://www.securitytracker.com/id?1026990https://bugzilla.redhat.com/show_bug.cgi?id=747078https://issues.apache.org/jira/browse/QPID-3652https://reviews.apache.org/r/2988/
2012-05-03
Published