VYPR
Moderate severityNVD Advisory· Published Aug 27, 2012· Updated Apr 29, 2026

CVE-2012-3467

CVE-2012-3467

Description

Apache QPID 0.14, 0.16, and earlier uses a NullAuthenticator mechanism to authenticate catch-up shadow connections to AMQP brokers, which allows remote attackers to bypass authentication.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.qpid:qpid-parentMaven
< 0.170.17

Affected products

4
  • Apache/Qpid4 versions
    cpe:2.3:a:apache:qpid:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:apache:qpid:*:*:*:*:*:*:*:*range: <=0.16
    • cpe:2.3:a:apache:qpid:0.5:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:qpid:0.6:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:qpid:0.14:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

13

News mentions

0

No linked articles in our index yet.