CVE-2012-3467: Apache Qpid
Medium severity, CVSS 5.0. EPSS: 6.4% chance of exploitation in the next 30 days.
Apache QPID 0.14, 0.16, and earlier uses a NullAuthenticator mechanism to authenticate catch-up shadow connections to AMQP brokers, which allows remote attackers to bypass authentication.
Affected products
- Apache Qpid: up to and including 0.16; version 0.5 only; version 0.6 only; version 0.14 only
Published 2012-08-27. Last modified 2026-06-16.