First published: Sun Feb 02 2014(Updated: )
The python-qpid client (common/rpc/impl_qpid.py) in OpenStack Oslo before 2013.2 does not enforce SSL connections when qpid_protocol is set to ssl, which allows remote attackers to obtain sensitive information by sniffing the network.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
OpenStack Oslo | <=2013 | |
Red Hat OpenStack for IBM Power | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-6491 is classified as a moderate severity vulnerability.
To fix CVE-2013-6491, ensure that SSL connections are properly enforced in the configuration settings of OpenStack Oslo.
CVE-2013-6491 affects OpenStack Oslo versions before 2013.2.
Yes, CVE-2013-6491 can allow remote attackers to sniff network traffic and potentially obtain sensitive information.
Yes, CVE-2013-6491 is exploitable remotely by attackers who can access the network.