Improper Authentication in Apache Qpid
Moderate severity
GitHub Reviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Mar 14, 2013
Published to the GitHub Advisory Database
May 17, 2022
Reviewed
Jul 13, 2022
Last updated
Jan 27, 2023
The default configuration for Apache Qpid 0.20 and earlier, when the federation_tag attribute is enabled, accepts AMQP connections without checking the source user ID, which allows remote attackers to bypass authentication and have other unspecified impact via an AMQP request.
References