CVE-2012-4446
published 2013-03-14CVE-2012-4446: The default configuration for Apache Qpid 0.20 and earlier, when the federation_tag attribute is enabled, accepts AMQP connections without checking the source…
PriorityP341medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
4.91%
91.1th percentile
The default configuration for Apache Qpid 0.20 and earlier, when the federation_tag attribute is enabled, accepts AMQP connections without checking the source user ID, which allows remote attackers to bypass authentication and have other unspecified impact via an AMQP request.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | qpid | <= 0.20 | — |
| apache | qpid | — | — |
| apache | qpid | — | — |
| apache | qpid | — | — |
| apache | qpid | — | — |
| apache | qpid | — | — |
| apache | qpid | — | — |
| apache | qpid | — | — |
| apache | qpid | — | — |
| apache | qpid | — | — |
| apache | qpid | — | — |
| apache | qpid | — | — |
| apache | qpid | — | — |
| apache | qpid | — | — |
| apache | qpid | — | — |
| apache | qpid | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Improper Authentication in Apache Qpid
osv·2022-05-17
CVE-2012-4446 [MEDIUM] Improper Authentication in Apache Qpid
Improper Authentication in Apache Qpid
The default configuration for Apache Qpid 0.20 and earlier, when the federation_tag attribute is enabled, accepts AMQP connections without checking the source user ID, which allows remote attackers to bypass authentication and have other unspecified impact via an AMQP request.
GHSA
Improper Authentication in Apache Qpid
ghsa·2022-05-17
CVE-2012-4446 [MEDIUM] CWE-287 Improper Authentication in Apache Qpid
Improper Authentication in Apache Qpid
The default configuration for Apache Qpid 0.20 and earlier, when the federation_tag attribute is enabled, accepts AMQP connections without checking the source user ID, which allows remote attackers to bypass authentication and have other unspecified impact via an AMQP request.
OSV
CVE-2012-4446: The default configuration for Apache Qpid 0
osv·2013-03-14·CVSS 6.8
CVE-2012-4446 [MEDIUM] CVE-2012-4446: The default configuration for Apache Qpid 0
The default configuration for Apache Qpid 0.20 and earlier, when the federation_tag attribute is enabled, accepts AMQP connections without checking the source user ID, which allows remote attackers to bypass authentication and have other unspecified impact via an AMQP request.
Red Hat
qpid-cpp: qpid authentication bypass
vendor_redhat·2013-03-06·CVSS 6.8
CVE-2012-4446 [MEDIUM] qpid-cpp: qpid authentication bypass
qpid-cpp: qpid authentication bypass
The default configuration for Apache Qpid 0.20 and earlier, when the federation_tag attribute is enabled, accepts AMQP connections without checking the source user ID, which allows remote attackers to bypass authentication and have other unspecified impact via an AMQP request.
It was found that the Apache Qpid daemon (qpidd) treated AMQP connections with the federation_tag attribute set as a broker-to-broker connection, rather than a client-to-server connection. This resulted in the source user ID of messages not being checked. A client that can establish an AMQP connection with the broker could use this flaw to bypass intended authentication. For Condor users, if condor-aviary is installed, this flaw could be used to submit jobs that would run as any
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-4446 CVE-2012-4458 CVE-2012-4459 qpid-cpp various flaws [fedora-all]
bugzilla·2013-03-06·CVSS 6.8
CVE-2012-4446 [MEDIUM] CVE-2012-4446 CVE-2012-4458 CVE-2012-4459 qpid-cpp various flaws [fedora-all]
CVE-2012-4446 CVE-2012-4458 CVE-2012-4459 qpid-cpp various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue aff
Bugzilla
CVE-2012-4446 qpid-cpp: qpid authentication bypass
bugzilla·2012-08-23·CVSS 6.8
CVE-2012-4446 [MEDIUM] CVE-2012-4446 qpid-cpp: qpid authentication bypass
CVE-2012-4446 qpid-cpp: qpid authentication bypass
Florian Weimer of the Red Hat Product Security Team discovered that setting the federation_tag attribute in an AMQP connection would turn the connection into a broker-to-broker connection, rather than a client-to-server connection. Because of this, incoming user IDs are not checked, so if a client were to set the federation_tag attribute when establishing a regular AMQP connection, Qpid would no longer check the user ID on AMQP messages submitted by the client. The client can then supply any value and thus impersonate any user, since AMQP messages carry user information that identify the sender and message recipients, which use user names for authentication purposes. The client does have to authenticate, but any authentication method, inc
http://rhn.redhat.com/errata/RHSA-2013-0561.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0562.htmlhttp://secunia.com/advisories/52516https://bugzilla.redhat.com/show_bug.cgi?id=851355https://issues.apache.org/jira/browse/QPID-4631http://rhn.redhat.com/errata/RHSA-2013-0561.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0562.htmlhttp://secunia.com/advisories/52516https://bugzilla.redhat.com/show_bug.cgi?id=851355https://issues.apache.org/jira/browse/QPID-4631
2013-03-14
Published