|
|
Subscribe / Log in / New account

MRG Messaging 2.2: authentication bypass

Package(s):MRG Messaging 2.2 CVE #(s):CVE-2012-3467
Created:September 20, 2012 Updated:September 26, 2012
Description:

From the Red Hat advisory:

It was discovered that qpidd did not require authentication for "catch-up" shadow connections created when a new broker joins a cluster. A malicious client could use this flaw to bypass client authentication. (CVE-2012-3467)

Alerts:
Red Hat RHSA-2012:1279-01 MRG Messaging 2.2 2012-09-19
Red Hat RHSA-2012:1277-01 MRG Messaging 2.2 2012-09-19

to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds