CVE-2012-3467

Currently unrated

Key Information:

Vendor
Apache
Status
Vendor
CVE Published:
27 August 2012

Summary

Apache QPID 0.14, 0.16, and earlier uses a NullAuthenticator mechanism to authenticate catch-up shadow connections to AMQP brokers, which allows remote attackers to bypass authentication.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.