Moderate severityNVD Advisory· Published Mar 14, 2013· Updated Apr 29, 2026
CVE-2012-4446
CVE-2012-4446
Description
The default configuration for Apache Qpid 0.20 and earlier, when the federation_tag attribute is enabled, accepts AMQP connections without checking the source user ID, which allows remote attackers to bypass authentication and have other unspecified impact via an AMQP request.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.qpid:qpid-clientMaven | < 0.20 | 0.20 |
Affected products
16cpe:2.3:a:apache:qpid:*:*:*:*:*:*:*:*+ 15 more
- cpe:2.3:a:apache:qpid:*:*:*:*:*:*:*:*range: <=0.20
- cpe:2.3:a:apache:qpid:0.10:*:*:*:*:*:*:*
- cpe:2.3:a:apache:qpid:0.11:*:*:*:*:*:*:*
- cpe:2.3:a:apache:qpid:0.12:*:*:*:*:*:*:*
- cpe:2.3:a:apache:qpid:0.13:*:*:*:*:*:*:*
- cpe:2.3:a:apache:qpid:0.14:*:*:*:*:*:*:*
- cpe:2.3:a:apache:qpid:0.15:*:*:*:*:*:*:*
- cpe:2.3:a:apache:qpid:0.16:*:*:*:*:*:*:*
- cpe:2.3:a:apache:qpid:0.17:*:*:*:*:*:*:*
- cpe:2.3:a:apache:qpid:0.18:*:*:*:*:*:*:*
- cpe:2.3:a:apache:qpid:0.19:*:*:*:*:*:*:*
- cpe:2.3:a:apache:qpid:0.5:*:*:*:*:*:*:*
- cpe:2.3:a:apache:qpid:0.6:*:*:*:*:*:*:*
- cpe:2.3:a:apache:qpid:0.7:*:*:*:*:*:*:*
- cpe:2.3:a:apache:qpid:0.8:*:*:*:*:*:*:*
- cpe:2.3:a:apache:qpid:0.9:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- secunia.com/advisories/52516nvdVendor Advisory
- github.com/advisories/GHSA-mrgh-6x42-x6xfghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2012-4446ghsaADVISORY
- rhn.redhat.com/errata/RHSA-2013-0561.htmlnvdWEB
- rhn.redhat.com/errata/RHSA-2013-0562.htmlnvdWEB
- bugzilla.redhat.com/show_bug.cginvdWEB
- issues.apache.org/jira/browse/QPID-4631nvdWEB
News mentions
0No linked articles in our index yet.