REDHAT-BUG-1186308: Medium severity apache qpid vulnerability
It was reported [1] that an attacker can gain access to qpidd as an anonymous user, even if the ANONYMOUS mechanism is disallowed.
A patch is available (https://issues.apache.org/jira/browse/QPID-6325) that addresses this vulnerability. The fix will be included in subsequent releases, but can be applied to 0.30 if desired.
[1]: http://seclists.org/bugtraq/2015/Jan/122
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1186308?
The severity of REDHAT-BUG-1186308 is high, as it allows unauthorized access to qpidd by anonymous users.
How do I fix REDHAT-BUG-1186308?
To fix REDHAT-BUG-1186308, apply the available patch from the Apache Qpid project.
Which versions of Apache Qpid are affected by REDHAT-BUG-1186308?
Apache Qpid versions up to but not including 0.30 are affected by REDHAT-BUG-1186308.
Can an attacker exploit REDHAT-BUG-1186308 even if anonymous access is disabled?
Yes, an attacker can exploit REDHAT-BUG-1186308 to gain access to qpidd as an anonymous user, irrespective of the ANONYMOUS mechanism being disallowed.
What is the primary issue with REDHAT-BUG-1186308?
The primary issue with REDHAT-BUG-1186308 is that it allows unauthorized access, compromising the security of the qpidd service.