CVE-2013-6491: Medium severity Openstack Oslo vulnerability
Published Feb 2, 2014
·Updated
The python-qpid client (common/rpc/implqpid.py) in OpenStack Oslo before 2013.2 does not enforce SSL connections when qpidprotocol is set to ssl, which allows remote attackers to obtain sensitive information by sniffing the network.
Affected Software
2 affected components
Openstack Oslo<=2013
redhat Openstack=3.0
Event History
Feb 2, 2014
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·12:55 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-6491?
CVE-2013-6491 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2013-6491?
To fix CVE-2013-6491, ensure that SSL connections are properly enforced in the configuration settings of OpenStack Oslo.
3
Which versions of OpenStack Oslo are affected by CVE-2013-6491?
CVE-2013-6491 affects OpenStack Oslo versions before 2013.2.
4
Can CVE-2013-6491 lead to data breaches?
Yes, CVE-2013-6491 can allow remote attackers to sniff network traffic and potentially obtain sensitive information.
5
Is CVE-2013-6491 exploitable remotely?
Yes, CVE-2013-6491 is exploitable remotely by attackers who can access the network.