Authentication Bypass in Apache Qpid Broker-J by Remote Attackers
CVE-2017-15702

9.8CRITICAL

Key Information:

Vendor

Apache

Vendor
CVE Published:
1 December 2017

What is CVE-2017-15702?

In versions 0.18 to 0.32 of Apache Qpid Broker-J, a misconfiguration of authentication providers across different ports can expose the broker to remote unauthenticated attacks. If one of the configured ports operates over HTTP, an attacker can connect to it and exploit authentication mechanisms intended for a different, potentially less secure, port. This vulnerability allows for the circumvention of firewall protections, especially when the targeted authentication on the spoofed port lacks rigorous security measures, such as accepting anonymous access or using default account credentials. It is important to note that versions 6.0.0 and newer are not affected by this flaw.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Apache Qpid Broker-J 0.18 through 0.32

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.