Security Advisory

CVE-2013-6491

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2014-02-02 00:00:00
Last updated 2024-08-06 17:46:22
Assigner redhat
State PUBLISHED

Description

The python-qpid client (common/rpc/impl_qpid.py) in OpenStack Oslo before 2013.2 does not enforce SSL connections when qpid_protocol is set to ssl, which allows remote attackers to obtain sensitive information by sniffing the network.