First published: Mon Jan 13 2014(Updated: )
It was discovered that Qpid authentication was disabled by default in the standalone controller quickstack manifest. If this was used in a production system without change then anyone able to make a TCP connection to Qpid would have unauthenticated access to any OpenStack backends using Qpid (such as Nova).
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat OpenStack for IBM Power | =4.0 | |
=4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-6470 has been classified as a critical vulnerability due to the potential for unauthenticated access.
To fix CVE-2013-6470, enable Qpid authentication in the Quickstack manifest to prevent unauthorized access.
CVE-2013-6470 affects Red Hat OpenStack version 4.0.
CVE-2013-6470 allows unauthenticated access to OpenStack backends via Qpid.
Yes, CVE-2013-6470 can be exploited remotely by anyone capable of establishing a TCP connection to Qpid.