CVE-2013-6491
OpenStack Oslo < 2013.2 - Unauthenticated Sensitive Information Exposure via Qpid SSL Enforcement Bypass
Title source: llmDescription
The python-qpid client (common/rpc/impl_qpid.py) in OpenStack Oslo before 2013.2 does not enforce SSL connections when qpid_protocol is set to ssl, which allows remote attackers to obtain sensitive information by sniffing the network.
References (4)
Core 4
Core References
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-0112.html
Issue Tracking x_refsource_confirm
https://bugs.launchpad.net/oslo/+bug/1158807
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=996766
Vendor Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2247-1
Scores
EPSS
0.0046
EPSS Percentile
64.1%
Details
CWE
CWE-310
Status
published
Products (2)
openstack/oslo
< 2013
redhat/openstack
3.0
Published
Feb 02, 2014
Tracked Since
Feb 18, 2026