CVE-2013-6491
02.02.2014, 00:55
The python-qpid client (common/rpc/impl_qpid.py) in OpenStack Oslo before 2013.2 does not enforce SSL connections when qpid_protocol is set to ssl, which allows remote attackers to obtain sensitive information by sniffing the network.Enginsight
| Vendor | Product | Version |
|---|---|---|
| openstack | oslo | 𝑥 ≤ 2013 |
| redhat | openstack | 3.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| cinder |
| ||||||||||
| keystone |
| ||||||||||
| neutron |
| ||||||||||
| nova |
| ||||||||||
| quantum |
|
Common Weakness Enumeration
References