Back

CRITICAL

qpid-java: Authentication bypass

Published Jun 1, 2016

Description

The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication and consequently perform actions via vectors related to connection state logging.

Affected products

Remediation

Red Hat statement

This issue did not affect the versions of the qpid -java broker as shipped with Red Hat MRG 2 and 3 and Satellite 6 as they did not use the access feature (e.g. Satellite 6 relies on client certificate authentication to control access).

Red Hat mitigation

If upgrading is not possible, the vulnerability can be mitigated using an ACL file containing "ACCESS VIRTUALHOST" clauses that white-lists user access to all virtualhosts. If AMQP 0-8, 0-9, 0-91, and 0-10 support is not required, the vulnerability can also be mitigated by turning off these protocols at the Port level.

Metrics

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jun 1, 2016
Updated Aug 6, 2024
Reserved May 2, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date May 27, 2016
GHSA-Q66C-H853-GQW2