CVE-2016-8741
published 2017-05-15CVE-2016-8741: The Apache Qpid Broker for Java can be configured to use different so called AuthenticationProviders to handle user authentication. Among the choices are the…
PriorityP349high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
6.18%
92.7th percentile
The Apache Qpid Broker for Java can be configured to use different so called AuthenticationProviders to handle user authentication. Among the choices are the SCRAM-SHA-1 and SCRAM-SHA-256 AuthenticationProvider types. It was discovered that these AuthenticationProviders in Apache Qpid Broker for Java 6.0.x before 6.0.6 and 6.1.x before 6.1.1 prematurely terminate the SCRAM SASL negotiation if the provided user name does not exist thus allowing remote attacker to determine the existence of user accounts. The Vulnerability does not apply to AuthenticationProviders other than SCRAM-SHA-1 and SCRAM-SHA-256.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | qpid_broker-j | — | — |
| apache | qpid_broker-j | — | — |
| apache | qpid_broker-j | — | — |
| apache | qpid_broker-j | — | — |
| apache | qpid_broker-j | — | — |
| apache | qpid_broker-j | — | — |
| apache_software_foundation | apache_qpid_broker-j | — | — |
| apache_software_foundation | apache_qpid_broker-j | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Exposure of Sensitive Information to an Unauthorized Actor in Apache Qpid Broker for Java
ghsa·2022-05-17
CVE-2016-8741 [HIGH] CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in Apache Qpid Broker for Java
Exposure of Sensitive Information to an Unauthorized Actor in Apache Qpid Broker for Java
The Apache Qpid Broker for Java can be configured to use different so called AuthenticationProviders to handle user authentication. Among the choices are the SCRAM-SHA-1 and SCRAM-SHA-256 AuthenticationProvider types. It was discovered that these AuthenticationProviders in Apache Qpid Broker for Java 6.0.x before 6.0.6 and 6.1.x before 6.1.1 prematurely terminate the SCRAM SASL negotiation if the provided user name does not exist thus allowing remote attacker to determine the existence of user accounts. The Vulnerability does not apply to AuthenticationProviders other than SCRAM-SHA-1 and SCRAM-SHA-256.
OSV
Exposure of Sensitive Information to an Unauthorized Actor in Apache Qpid Broker for Java
osv·2022-05-17
CVE-2016-8741 [HIGH] Exposure of Sensitive Information to an Unauthorized Actor in Apache Qpid Broker for Java
Exposure of Sensitive Information to an Unauthorized Actor in Apache Qpid Broker for Java
The Apache Qpid Broker for Java can be configured to use different so called AuthenticationProviders to handle user authentication. Among the choices are the SCRAM-SHA-1 and SCRAM-SHA-256 AuthenticationProvider types. It was discovered that these AuthenticationProviders in Apache Qpid Broker for Java 6.0.x before 6.0.6 and 6.1.x before 6.1.1 prematurely terminate the SCRAM SASL negotiation if the provided user name does not exist thus allowing remote attacker to determine the existence of user accounts. The Vulnerability does not apply to AuthenticationProviders other than SCRAM-SHA-1 and SCRAM-SHA-256.
Red Hat
qpid-java: Information leakage via specific AuthenticationProviders
vendor_redhat·2016-12-28·CVSS 7.5
CVE-2016-8741 [HIGH] CWE-200 qpid-java: Information leakage via specific AuthenticationProviders
qpid-java: Information leakage via specific AuthenticationProviders
The Apache Qpid Broker for Java can be configured to use different so called AuthenticationProviders to handle user authentication. Among the choices are the SCRAM-SHA-1 and SCRAM-SHA-256 AuthenticationProvider types. It was discovered that these AuthenticationProviders in Apache Qpid Broker for Java 6.0.x before 6.0.6 and 6.1.x before 6.1.1 prematurely terminate the SCRAM SASL negotiation if the provided user name does not exist thus allowing remote attacker to determine the existence of user accounts. The Vulnerability does not apply to AuthenticationProviders other than SCRAM-SHA-1 and SCRAM-SHA-256.
Package: qpid-java (Red Hat Enterprise MRG 2) - Not affected
Package: qpid-java (Red Hat Enterprise MRG 3) - Not affec
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-8741 qpid-java: Information leakage via specific AuthenticationProviders
bugzilla·2017-01-03·CVSS 7.5
CVE-2016-8741 [HIGH] CVE-2016-8741 qpid-java: Information leakage via specific AuthenticationProviders
CVE-2016-8741 qpid-java: Information leakage via specific AuthenticationProviders
The Qpid Broker for Java can be configured to use different so
called AuthenticationProviders to handle user authentication.
Among the choices are the SCRAM-SHA-1 and SCRAM-SHA-256
AuthenticationProvider types.
It was discovered that these AuthenticationProviders prematurely
terminate the SCRAM SASL negotiation if the provided user name
does not exist thus allowing remote attacker to determine the
existence of user accounts.
The Vulnerability does not apply to AuthenticationProviders other
than SCRAM-SHA-1 and SCRAM-SHA-256.
References:
http://seclists.org/oss-sec/2016/q4/772
Upstream bug:
https://issues.apache.org/jira/browse/QPID-7599
Discussion:
Created qpid-java tracking bugs for this issue:
Af
Bugzilla
CVE-2016-8741 qpid-java: Information leakage via specific AuthenticationProviders [fedora-all]
bugzilla·2017-01-03·CVSS 7.5
CVE-2016-8741 [HIGH] CVE-2016-8741 qpid-java: Information leakage via specific AuthenticationProviders [fedora-all]
CVE-2016-8741 qpid-java: Information leakage via specific AuthenticationProviders [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppo
http://qpid.2158936.n2.nabble.com/CVE-2016-8741-Apache-Qpid-Broker-for-Java-Information-Leakage-td7657025.htmlhttp://www.securityfocus.com/bid/95136http://www.securitytracker.com/id/1037537https://issues.apache.org/jira/browse/QPID-7599http://qpid.2158936.n2.nabble.com/CVE-2016-8741-Apache-Qpid-Broker-for-Java-Information-Leakage-td7657025.htmlhttp://www.securityfocus.com/bid/95136http://www.securitytracker.com/id/1037537https://issues.apache.org/jira/browse/QPID-7599
2017-05-15
Published