CVE-2013-6491
02.02.2014, 00:55
The python-qpid client (common/rpc/impl_qpid.py) in OpenStack Oslo before 2013.2 does not enforce SSL connections when qpid_protocol is set to ssl, which allows remote attackers to obtain sensitive information by sniffing the network.Enginsight
Vendor | Product | Version |
---|---|---|
openstack | oslo | 𝑥 ≤ 2013 |
redhat | openstack | 3.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
cinder |
| ||||||||||
keystone |
| ||||||||||
neutron |
| ||||||||||
nova |
| ||||||||||
quantum |
|
Common Weakness Enumeration
References