Authentication Bypass in Apache Qpid Broker-J by Remote Attackers
CVE-2017-15702
What is CVE-2017-15702?
In versions 0.18 to 0.32 of Apache Qpid Broker-J, a misconfiguration of authentication providers across different ports can expose the broker to remote unauthenticated attacks. If one of the configured ports operates over HTTP, an attacker can connect to it and exploit authentication mechanisms intended for a different, potentially less secure, port. This vulnerability allows for the circumvention of firewall protections, especially when the targeted authentication on the spoofed port lacks rigorous security measures, such as accepting anonymous access or using default account credentials. It is important to note that versions 6.0.0 and newer are not affected by this flaw.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Apache Qpid Broker-J 0.18 through 0.32
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved