CVE-2012-3467

Apache Qpid < 0.16 - Authentication Bypass

Title source: rule

Description

Apache QPID 0.14, 0.16, and earlier uses a NullAuthenticator mechanism to authenticate catch-up shadow connections to AMQP brokers, which allows remote attackers to bypass authentication.

Scores

EPSS 0.0115
EPSS Percentile 78.2%

Classification

CWE
CWE-287
Status draft

Affected Products (5)

apache/qpid < 0.16
apache/qpid
apache/qpid
apache/qpid
org.apache.qpid/qpid-parent < 0.17Maven

Timeline

Published Aug 27, 2012
Tracked Since Feb 18, 2026