Description
The python-qpid client (common/rpc/impl_qpid.py) in OpenStack Oslo before 2013.2 does not enforce SSL connections when qpid_protocol is set to ssl, which allows remote attackers to obtain sensitive information by sniffing the network.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2013-6294 | The python-qpid client (common/rpc/impl_qpid.py) in OpenStack Oslo before 2013.2 does not enforce SSL connections when qpid_protocol is set to ssl, which allows remote attackers to obtain sensitive information by sniffing the network. |
Ubuntu USN |
USN-2208-1 | OpenStack Cinder vulnerability |
Ubuntu USN |
USN-2208-2 | OpenStack Quantum vulnerability |
Ubuntu USN |
USN-2247-1 | OpenStack Nova vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T17:46:22.030Z
Reserved: 2013-11-04T00:00:00.000Z
Link: CVE-2013-6491
No data.
Status : Deferred
Published: 2014-02-02T00:55:04.647
Modified: 2025-04-11T00:51:21.963
Link: CVE-2013-6491
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Ubuntu USN