Moderate
Qpid C++ broker
0.30 and earlier
0.32 and later
Anonymous access to qpidd cannot be prevented.
An attacker can gain access to qpidd as an anonymous user, even if the ANONYMOUS mechanism is disallowed.
A patch is available (QPID-6325) that addresses this vulnerability. The fix will be included in subsequent releases, but can be applied to 0.30 if desired.
Authorization can be used to restrict access to broker entities such as queue and exchanges.
This issue was discovered by G. Geshev from MWR Labs.
Apache Qpid, Messaging built on AMQP; Copyright © 2015 The Apache Software Foundation; Licensed under the Apache License, Version 2.0; Apache Qpid, Qpid, Qpid Proton, Proton, Apache, the Apache feather logo, and the Apache Qpid project logo are trademarks of The Apache Software Foundation; All other marks mentioned may be trademarks or registered trademarks of their respective owners