CVE-2013-6491

OpenStack Oslo < 2013.2 - Unauthenticated Sensitive Information Exposure via Qpid SSL Enforcement Bypass

Title source: llm
STIX 2.1

Description

The python-qpid client (common/rpc/impl_qpid.py) in OpenStack Oslo before 2013.2 does not enforce SSL connections when qpid_protocol is set to ssl, which allows remote attackers to obtain sensitive information by sniffing the network.

References (4)

Core 4
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-0112.html
Issue Tracking x_refsource_confirm
https://bugs.launchpad.net/oslo/+bug/1158807
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=996766
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2247-1

Scores

EPSS 0.0046
EPSS Percentile 64.1%

Details

CWE
CWE-310
Status published
Products (2)
openstack/oslo < 2013
redhat/openstack 3.0
Published Feb 02, 2014
Tracked Since Feb 18, 2026