Description
The default configuration for Apache Qpid 0.20 and earlier, when the federation_tag attribute is enabled, accepts AMQP connections without checking the source user ID, which allows remote attackers to bypass authentication and have other unspecified impact via an AMQP request.
Remediation
References
http://rhn.redhat.com/errata/RHSA-2013-0561.html
http://rhn.redhat.com/errata/RHSA-2013-0562.html
http://secunia.com/advisories/52516
https://bugzilla.redhat.com/show_bug.cgi?id=851355
https://issues.apache.org/jira/browse/QPID-4631
Related Vulnerabilities
CVE-2018-20677 Vulnerability in maven package org.webjars:bootstrap
CVE-2020-1695 Vulnerability in maven package org.jboss.resteasy:resteasy-jaxrs-all
CVE-2018-1000197 Vulnerability in maven package com.blackducksoftware.integration:blackduck-hub
CVE-2018-19413 Vulnerability in maven package org.sonarsource.sonarqube:sonar-plugin-api
CVE-2020-11969 Vulnerability in maven package org.apache.tomee:openejb-lite