CVE-2011-3620: High severity apache qpid vulnerability
A flaw was found in qpid where it would accept any password or SASL mechanism, provided the remote user knew a valid cluster username. This would give a malicious remote attacker unauthorized access to the cluster where they would be able to receive replicated messages to the cluster, be able to send any cluster message, mark any present message as consumed, run any job on the cluster, and also view/modify/create other users' jobs. Only cluster messages and internal qpid/MRG configuration is accessible to the remote attacker.
Other sources
Apache Qpid 0.12 does not properly verify credentials during the joining of a cluster, which allows remote attackers to obtain access to the messaging functionality and job functionality of a cluster by leveraging knowledge of a cluster-username.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3620?
CVE-2011-3620 is considered a high severity vulnerability allowing unauthorized access to an Apache Qpid cluster.
How do I fix CVE-2011-3620?
To fix CVE-2011-3620, upgrade to a version of Apache Qpid that is patched against this vulnerability.
Who is affected by CVE-2011-3620?
Users of Apache Qpid version 0.12 are affected by CVE-2011-3620.
What type of attack is possible with CVE-2011-3620?
CVE-2011-3620 allows remote attackers to gain unauthorized access and receive replicated messages in the cluster.
Is CVE-2011-3620 related to password security?
Yes, CVE-2011-3620 involves the acceptance of any password or SASL mechanism if a valid cluster username is known.