Apache Qpid 0.12 Cluster Joining Vulnerability

Apache Qpid 0.12 Cluster Joining Vulnerability

CVE-2011-3620 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

Apache Qpid 0.12 does not properly verify credentials during the joining of a cluster, which allows remote attackers to obtain access to the messaging functionality and job functionality of a cluster by leveraging knowledge of a cluster-username.

Learn more about our User Device Pen Test.