Red Hat Bugzilla – Bug 1051994
CVE-2013-6470 openstack foreman-installer: insecure defaults
Last modified: 2016-04-26 13:57:08 EDT
It was discovered that Qpid authentication was disabled by default in the standalone controller quickstack manifest. If this was used in a production system without change then anyone able to make a TCP connection to Qpid would have unauthenticated access to any OpenStack backends using Qpid (such as Nova).
This issue has been addressed in following products: OpenStack 4 for RHEL 6 Via RHSA-2014:0517 https://rhn.redhat.com/errata/RHSA-2014-0517.html