Apache Qpid Security Restriction Bypass Vulnerability (CVE-2015-0223)
Release date:
Updated on:
Affected Systems:
Apache Group Qpid <= 0.30
Description:
Bugtraq id: 72319
CVE (CAN) ID: CVE-2015-0223
Apache Qpid (Open Source AMQP Messaging) is a cross-platform enterprise communication solution that implements the Advanced Message Queue Protocol.
Apache Qpid versions earlier than qpidd 0.31 have security vulnerabilities in the implementation of the access mechanism. Attackers can also access qpidd when the ANONYMOUS mechanism is disabled and perform unauthorized operations.
<* Source: G. gesev
*>
Suggestion:
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://issues.apache.org/jira/secure/attachment/12694233/QPID-6325.patch
Https://issues.apache.org/jira/browse/QPID-6325
Introduction to message-oriented middleware Apache Qpid
Qpid details: click here
Qpid: click here
This article permanently updates the link address: