CVE-2011-3620
Apache Qpid 0.12 - Auth Bypass
Title source: llmDescription
Apache Qpid 0.12 does not properly verify credentials during the joining of a cluster, which allows remote attackers to obtain access to the messaging functionality and job functionality of a cluster by leveraging knowledge of a cluster-username.
References (5)
Scores
EPSS
0.0298
EPSS Percentile
86.4%
Classification
CWE
CWE-287
Status
draft
Affected Products (1)
apache/qpid
Timeline
Published
May 03, 2012
Tracked Since
Feb 18, 2026