CVE-2015-0223: Medium severity apache qpid vulnerability
It was reported [1] that an attacker can gain access to qpidd as an anonymous user, even if the ANONYMOUS mechanism is disallowed.
A patch is available (https://issues.apache.org/jira/browse/QPID-6325) that addresses this vulnerability. The fix will be included in subsequent releases, but can be applied to 0.30 if desired.
[1]: http://seclists.org/bugtraq/2015/Jan/122
Other sources
Unspecified vulnerability in Apache Qpid 0.30 and earlier allows remote attackers to bypass access restrictions on qpidd via unknown vectors, related to 0-10 connection handling.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0223?
CVE-2015-0223 is classified as a high severity vulnerability, allowing unauthorized access to Apache Qpid.
How do I fix CVE-2015-0223?
To fix CVE-2015-0223, upgrade Apache Qpid to a version higher than 0.30.
What systems are affected by CVE-2015-0223?
CVE-2015-0223 affects Apache Qpid versions 0.30 and earlier.
What are the potential exploits of CVE-2015-0223?
Attackers can exploit CVE-2015-0223 to bypass access restrictions on qpidd, gaining unauthorized access.
Is there a workaround for CVE-2015-0223?
Currently, there are no known effective workarounds for CVE-2015-0223 other than upgrading to a patched version.