The python-qpid client (common/rpc/impl_qpid.py) in OpenStack Oslo before 2013.2 does not enforce SSL connections when qpid_protocol is set to ssl, which allows remote attackers to obtain sensitive information by sniffing the network.
https://bugzilla.redhat.com/show_bug.cgi?id=996766
https://bugs.launchpad.net/oslo/+bug/1158807