Moderate severityNVD Advisory· Published Aug 27, 2012· Updated Apr 29, 2026
CVE-2012-3467
CVE-2012-3467
Description
Apache QPID 0.14, 0.16, and earlier uses a NullAuthenticator mechanism to authenticate catch-up shadow connections to AMQP brokers, which allows remote attackers to bypass authentication.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.qpid:qpid-parentMaven | < 0.17 | 0.17 |
Affected products
4Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
13- secunia.com/advisories/50186nvdVendor Advisory
- github.com/advisories/GHSA-phw8-fw9g-v3xcghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2012-3467ghsaADVISORY
- rhn.redhat.com/errata/RHSA-2012-1277.htmlnvdWEB
- rhn.redhat.com/errata/RHSA-2012-1279.htmlnvdWEB
- svn.apache.org/viewvcnvdWEB
- www.openwall.com/lists/oss-security/2012/08/09/6nvdWEB
- bugzilla.redhat.com/show_bug.cginvdWEB
- exchange.xforce.ibmcloud.com/vulnerabilities/77568nvdWEB
- issues.apache.org/jira/browse/QPID-3849nvdWEB
- web.archive.org/web/20200229113556/http://www.securityfocus.com/bid/54954ghsaWEB
- secunia.com/advisories/50698nvd
- www.securityfocus.com/bid/54954nvd
News mentions
0No linked articles in our index yet.