CVE-2017-15702
published 2017-12-01CVE-2017-15702: In Apache Qpid Broker-J 0.18 through 0.32, if the broker is configured with different authentication providers on different ports one of which is an HTTP port…
PriorityP269critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
6.21%
92.7th percentile
In Apache Qpid Broker-J 0.18 through 0.32, if the broker is configured with different authentication providers on different ports one of which is an HTTP port, then the broker can be tricked by a remote unauthenticated attacker connecting to the HTTP port into using an authentication provider that was configured on a different port. The attacker still needs valid credentials with the authentication provider on the spoofed port. This becomes an issue when the spoofed port has weaker authentication protection (e.g., anonymous access, default accounts) and is normally protected by firewall rules or similar which can be circumvented by this vulnerability. AMQP ports are not affected. Versions 6.0.0 and newer are not affected.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | qpid_broker-j | 0.18 – 0.32 | — |
| apache_software_foundation | apache_qpid_broker-j | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Attack vector targets the HTTP port of Apache Qpid Broker-J; monitor for unauthenticated or anomalous authentication attempts on HTTP management ports of Qpid brokers running versions 0.18 through 0.32 ↗
- →AMQP ports are not affected; focus detection on HTTP port traffic to Qpid Broker-J instances, especially where weaker authentication (e.g., anonymous access, default accounts) may be exploited ↗
- →Affected versions are Apache Qpid Broker-J 0.18 through 0.32; flag any deployments of these versions with HTTP ports exposed, particularly where multiple authentication providers are configured across different ports ↗
- ·Vulnerability only manifests when the broker is configured with DIFFERENT authentication providers on different ports, at least one of which is an HTTP port; single-provider or non-HTTP configurations are not affected ↗
- ·Versions 6.0.0 and newer are not affected; ensure upgrade path is considered as primary remediation ↗
- ·The attacker still requires valid credentials for the spoofed (weaker) authentication provider — this is not a zero-credential bypass, but an authentication provider substitution issue ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
qpid-java: Authentication vulnerability on HTTP ports
vendor_redhat·2017-11-30·CVSS 9.8
CVE-2017-15702 [CRITICAL] CWE-287 qpid-java: Authentication vulnerability on HTTP ports
qpid-java: Authentication vulnerability on HTTP ports
In Apache Qpid Broker-J 0.18 through 0.32, if the broker is configured with different authentication providers on different ports one of which is an HTTP port, then the broker can be tricked by a remote unauthenticated attacker connecting to the HTTP port into using an authentication provider that was configured on a different port. The attacker still needs valid credentials with the authentication provider on the spoofed port. This becomes an issue when the spoofed port has weaker authentication protection (e.g., anonymous access, default accounts) and is normally protected by firewall rules or similar which can be circumvented by this vulnerability. AMQP ports are not affected. Versions 6.0.0 and newer are not affected.
Statement: R
OSV
Apache Qpid Broker vulnerable to authentication port spoofing
osv·2018-10-19
CVE-2017-15702 [CRITICAL] Apache Qpid Broker vulnerable to authentication port spoofing
Apache Qpid Broker vulnerable to authentication port spoofing
Apache Qpid Broker-J versions 0.18 through 0.32 are vulnerable to authentication port spoofing. When the broker is configured with different authentication providers on different ports, one of which is an HTTP port, then the broker can be tricked by a remote unauthenticated attacker connecting to the HTTP port into using an authentication provider that was configured on a different port. The attacker still needs valid credentials with the authentication provider on the spoofed port. This becomes an issue when the spoofed port has weaker authentication protection (e.g., anonymous access, default accounts) and is normally protected by firewall rules or similar which can be circumvented by this vulnerability. AMQP ports are not af
GHSA
Apache Qpid Broker vulnerable to authentication port spoofing
ghsa·2018-10-19
CVE-2017-15702 [CRITICAL] Apache Qpid Broker vulnerable to authentication port spoofing
Apache Qpid Broker vulnerable to authentication port spoofing
Apache Qpid Broker-J versions 0.18 through 0.32 are vulnerable to authentication port spoofing. When the broker is configured with different authentication providers on different ports, one of which is an HTTP port, then the broker can be tricked by a remote unauthenticated attacker connecting to the HTTP port into using an authentication provider that was configured on a different port. The attacker still needs valid credentials with the authentication provider on the spoofed port. This becomes an issue when the spoofed port has weaker authentication protection (e.g., anonymous access, default accounts) and is normally protected by firewall rules or similar which can be circumvented by this vulnerability. AMQP ports are not af
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/102040https://issues.apache.org/jira/browse/QPID-8039https://lists.apache.org/thread.html/59d241e30db23b8b0af26bb273f789aa1f08515d3dc1a3868d3ba090%40%3Cdev.qpid.apache.org%3Ehttps://qpid.apache.org/cves/CVE-2017-15702.htmlhttp://www.securityfocus.com/bid/102040https://issues.apache.org/jira/browse/QPID-8039https://lists.apache.org/thread.html/59d241e30db23b8b0af26bb273f789aa1f08515d3dc1a3868d3ba090%40%3Cdev.qpid.apache.org%3Ehttps://qpid.apache.org/cves/CVE-2017-15702.html
2017-12-01
Published