It was discovered that Qpid authentication was disabled by default in the standalone controller quickstack manifest.
If this was used in a production system without change then anyone able to make a TCP connection to Qpid would have unauthenticated access to any OpenStack backends using Qpid (such as Nova).