CVE-2017-15702 describes a critical vulnerability in Apache Qpid Broker-J versions 0.18 through 0.32, where a remote unauthenticated attacker can force the broker to use an authentication provider configured for a different port, specifically an HTTP port. This allows an attacker to bypass intended authentication mechanisms if the spoofed port has weaker security, potentially leading to full compromise (confidentiality, integrity, availability). Despite its critical CVSS score of 9.8, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.18, <= 0.32CPE matchmatch criteria | cpe:2.3:a:apache:qpid_broker-j:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.