Lucene search

K
cve[email protected]CVE-2013-6491
HistoryFeb 02, 2014 - 12:55 a.m.

CVE-2013-6491

2014-02-0200:55:04
CWE-310
web.nvd.nist.gov
29
cve-2013-6491
python-qpid
openstack oslo
ssl connections
network sniffing
nvd

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

5.9 Medium

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

65.9%

The python-qpid client (common/rpc/impl_qpid.py) in OpenStack Oslo before 2013.2 does not enforce SSL connections when qpid_protocol is set to ssl, which allows remote attackers to obtain sensitive information by sniffing the network.

Affected configurations

NVD
Node
openstackosloRange2013
OR
redhatopenstackMatch3.0

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

5.9 Medium

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

65.9%