CVE-2012-4446
Apache Qpid < 0.20 - Authentication Bypass
Title source: ruleDescription
The default configuration for Apache Qpid 0.20 and earlier, when the federation_tag attribute is enabled, accepts AMQP connections without checking the source user ID, which allows remote attackers to bypass authentication and have other unspecified impact via an AMQP request.
References (5)
Scores
EPSS
0.0044
EPSS Percentile
62.8%
Classification
CWE
CWE-287
Status
draft
Affected Products (17)
apache/qpid
< 0.20
apache/qpid
apache/qpid
apache/qpid
apache/qpid
apache/qpid
apache/qpid
apache/qpid
apache/qpid
apache/qpid
apache/qpid
apache/qpid
apache/qpid
apache/qpid
apache/qpid
... and 2 more
Timeline
Published
Mar 14, 2013
Tracked Since
Feb 18, 2026