First published: Mon Jan 13 2014(Updated: )
It was discovered that Qpid authentication was disabled by default in the standalone controller quickstack manifest. If this was used in a production system without change then anyone able to make a TCP connection to Qpid would have unauthenticated access to any OpenStack backends using Qpid (such as Nova).
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Openstack | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.