Moderate severityNVD Advisory· Published Mar 14, 2013· Updated Jun 16, 2026
CVE-2012-4446
CVE-2012-4446
Description
The default configuration for Apache Qpid 0.20 and earlier, when the federation_tag attribute is enabled, accepts AMQP connections without checking the source user ID, which allows remote attackers to bypass authentication and have other unspecified impact via an AMQP request.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.qpid:qpid-clientMaven | < 0.20 | 0.20 |
Affected products
17cpe:2.3:a:apache:qpid:*:*:*:*:*:*:*:*+ 15 more
- cpe:2.3:a:apache:qpid:*:*:*:*:*:*:*:*range: <=0.20
- cpe:2.3:a:apache:qpid:0.10:*:*:*:*:*:*:*
- cpe:2.3:a:apache:qpid:0.11:*:*:*:*:*:*:*
- cpe:2.3:a:apache:qpid:0.12:*:*:*:*:*:*:*
- cpe:2.3:a:apache:qpid:0.13:*:*:*:*:*:*:*
- cpe:2.3:a:apache:qpid:0.14:*:*:*:*:*:*:*
- cpe:2.3:a:apache:qpid:0.15:*:*:*:*:*:*:*
- cpe:2.3:a:apache:qpid:0.16:*:*:*:*:*:*:*
- cpe:2.3:a:apache:qpid:0.17:*:*:*:*:*:*:*
- cpe:2.3:a:apache:qpid:0.18:*:*:*:*:*:*:*
- cpe:2.3:a:apache:qpid:0.19:*:*:*:*:*:*:*
- cpe:2.3:a:apache:qpid:0.5:*:*:*:*:*:*:*
- cpe:2.3:a:apache:qpid:0.6:*:*:*:*:*:*:*
- cpe:2.3:a:apache:qpid:0.7:*:*:*:*:*:*:*
- cpe:2.3:a:apache:qpid:0.8:*:*:*:*:*:*:*
- cpe:2.3:a:apache:qpid:0.9:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
7- secunia.com/advisories/52516nvdVendor Advisory
- github.com/advisories/GHSA-mrgh-6x42-x6xfghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2012-4446ghsaADVISORY
- rhn.redhat.com/errata/RHSA-2013-0561.htmlnvdWEB
- rhn.redhat.com/errata/RHSA-2013-0562.htmlnvdWEB
- bugzilla.redhat.com/show_bug.cginvdWEB
- issues.apache.org/jira/browse/QPID-4631nvdWEB
News mentions
0No linked articles in our index yet.