Описание
RabbitMQ Stream Publisher Management API Discloses Unauthorized Vhost and Stream Existence
Advisory Details
Title: RabbitMQ Stream Publisher Management API Discloses Unauthorized Vhost and Stream Existence
Description:
Summary
RabbitMQ's Stream Management publisher endpoints return distinguishable responses for existing versus nonexistent vhosts and Stream queues before verifying whether the authenticated management user can access the requested vhost. A management-tagged user with no permissions on the target vhost receives 200 [] for an existing target and 404 for an absent target, enabling vhost and Stream queue name enumeration.
Details
The affected routes are GET /api/stream/publishers/:vhost and GET /api/stream/publishers/:vhost/:queue, implemented by rabbit_stream_publishers_mgmt.
At the highest affected release, RabbitMQ 4.3.2, is_authorized/2 uses only the general management authorization helper:
That check authenticates the caller and verifies a management-capable user tag, but it does not enforce access to the vhost provided in the route. The handler subsequently executes resource_exists/2, which looks up the supplied vhost and, for the queue-specific route, the supplied queue. The existence result determines whether Cowboy continues with a 200 response or returns 404.
The later filter_user/2 call suppresses publisher entries belonging to other users, but it cannot hide the status code selected earlier. The resulting response difference is an observable existence oracle across RabbitMQ's vhost isolation boundary.
The appropriate fix is to change rabbit_stream_publishers_mgmt:is_authorized/2 to use rabbit_mgmt_util:is_authorized_vhost/2, matching other vhost-scoped management handlers. This performs the vhost permission check before the existence lookup and makes inaccessible and missing targets externally indistinguishable.
PoC
Prerequisites
- Docker with access to the official
rabbitmq:4.3.1image - A RabbitMQ checkout with the PoC directory located at
llm-enhance/cve-finding/Info_Leak/Advisory-GHSA-j45q-v7g2-82ph-stream-publishers-vhost-authorization-exp/ - Management, Stream, and Stream Management plugins enabled by the environment script
- Local availability of TCP port
15672
The PoC provisions an isolated management-tagged user with no permissions on hidden-vhost. Administrator credentials are used only to create and inspect the local fixture; the vulnerable requests themselves use the restricted account.
Reproduction Steps
- Download run_experiment.sh, start_environment.sh, stop_environment.sh, verification_test.py, and control-missing-target.py into the PoC directory above
- Make the shell scripts executable and run
./run_experiment.sh - Observe
verification.log: requests bylimited:limited-passwordto the existing but unauthorizedhidden-vhostandhidden-streamreturn200with[] - Observe
control.log: requests with the same credentials tomissing-vhostandmissing-streamreturn404 - Inspect
observation.logfor the raw HTTP responses andmodule_path.logfor matching runtime and checkout-built module SHA-256 values
Log of Evidence
The end-to-end run against the isolated Broker produced:
limited-user-permissions.json contained [], confirming that the probing account had no permissions on hidden-vhost. enabled-plugins.log confirmed rabbitmq_management, rabbitmq_stream, and rabbitmq_stream_management were running. The SHA-256 of the container-loaded publisher handler matched the handler compiled from the checkout.
Impact
This is a cross-vhost metadata disclosure. An authenticated management user can test known or guessable vhost and Stream queue names belonging to other tenants or business units. The demonstrated behavior does not disclose message contents, publisher records, credentials, or permit unauthorized queue operations. However, vhost and Stream names commonly reveal deployment topology and business boundaries, and the oracle can support targeted follow-on reconnaissance.
Affected products
- Ecosystem: RabbitMQ Server
- Package name: rabbitmq-server
- Affected versions: <= 4.3.2
- Patched versions:
RabbitMQ 4.3.2 is the highest published GitHub release confirmed affected. Its release tag resolves to commit a509158b1b1e21c892a7f1dacbe0d158076dc7b8; the same vulnerable handler logic was also reproduced from the current checkout.
Severity
- Severity: Medium (CVSS 3.1: 4.3)
- Vector string: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weaknesses
- CWE: CWE-203: Observable Discrepancy
Occurrences
| Permalink | Description |
|---|---|
| https://github.com/rabbitmq/rabbitmq-server/blob/a509158b1b1e21c892a7f1dacbe0d158076dc7b8/deps/rabbitmq_stream_management/src/rabbit_stream_publishers_mgmt.erl#L39-L58 | resource_exists/2 resolves the attacker-controlled vhost and optional queue before a vhost authorization check, selecting the existence-dependent 200 or 404 path |
| https://github.com/rabbitmq/rabbitmq-server/blob/a509158b1b1e21c892a7f1dacbe0d158076dc7b8/deps/rabbitmq_stream_management/src/rabbit_stream_publishers_mgmt.erl#L96-L97 | is_authorized/2 invokes only tag-based management authorization instead of the vhost-aware authorization helper |
Пакеты
rabbitmq
>= 4.3.0, < 4.3.6
4.3.6
rabbitmq
>= 4.2.0, < 4.2.11
4.2.11
2.3 Low
CVSS4
Дефекты
2.3 Low
CVSS4