Details
-
Bug
-
Status: Closed
-
Critical
-
Resolution: Fixed
-
qpid-java-6.0.1, qpid-java-6.0.2, qpid-java-6.0.3, qpid-java-6.0.4, qpid-java-6.0.5, qpid-java-6.1
-
None
Description
SCRAM-SHA256 and SCRAM-SHA1 authentication providers prematurely terminate the SCRAM SASL negotiation if the provided user name does not exist thus allowing remote attacker to determine the existence of user accounts.
CVE-2016-8741 was raised for this issue.