Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-35789

Опубликовано: 16 июн. 2023
Источник: debian
EPSS Низкий

Описание

An issue was discovered in the C AMQP client library (aka rabbitmq-c) through 0.13.0 for RabbitMQ. Credentials can only be entered on the command line (e.g., for amqp-publish or amqp-consume) and are thus visible to local attackers by listing a process and its arguments.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
librabbitmqfixed0.14.0-1package
librabbitmqfixed0.11.0-1+deb12u1bookwormpackage
librabbitmqno-dsabusterpackage

Примечания

  • https://github.com/alanxz/rabbitmq-c/issues/575

  • https://github.com/alanxz/rabbitmq-c/commit/463054383fbeef889b409a7f843df5365288e2a0 (v0.14.0)

EPSS

Процентиль: 4%
0.0002
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 2 лет назад

An issue was discovered in the C AMQP client library (aka rabbitmq-c) through 0.13.0 for RabbitMQ. Credentials can only be entered on the command line (e.g., for amqp-publish or amqp-consume) and are thus visible to local attackers by listing a process and its arguments.

CVSS3: 5.1
redhat
около 2 лет назад

An issue was discovered in the C AMQP client library (aka rabbitmq-c) through 0.13.0 for RabbitMQ. Credentials can only be entered on the command line (e.g., for amqp-publish or amqp-consume) and are thus visible to local attackers by listing a process and its arguments.

CVSS3: 5.5
nvd
около 2 лет назад

An issue was discovered in the C AMQP client library (aka rabbitmq-c) through 0.13.0 for RabbitMQ. Credentials can only be entered on the command line (e.g., for amqp-publish or amqp-consume) and are thus visible to local attackers by listing a process and its arguments.

CVSS3: 5.5
msrc
6 месяцев назад

Описание отсутствует

suse-cvrf
около 2 лет назад

Security update for rabbitmq-c

EPSS

Процентиль: 4%
0.0002
Низкий
Уязвимость CVE-2023-35789