Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v9gv-xp36-jgj8

Опубликовано: 05 окт. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

Predictable credential obfuscation seed value used in Shovel and Federation plugins

Impact

Shovel and Federation plugins perform URI obfuscation in their worker (link) state. The encryption key used to encrypt the URI was seeded with a predictable secret.

This means that in case of certain exceptions related to Shovel and Federation plugins, reasonably easily deobfuscatable data could appear in the node log.

Patched versions correctly use a cluster-wide secret for that purpose.

Patches

Patched versions:

  • 3.10.2
  • 3.9.18
  • 3.8.32

Workarounds

Disable Shovel and Federation plugins.

Credits

RabbitMQ core team would like to thank Lajos @luos Gerecs and Anh Nguyen from Erlang Solutions for responsibly disclosing and working with us on a patch for this vulnerability.

For more information

Пакеты

Наименование

rabbitmq

vmware
Затронутые версииВерсия исправления

>= 3.10.0, <3.10.2

3.10.2

Наименование

rabbitmq

vmware
Затронутые версииВерсия исправления

>= 3.9.0, <3.9.18

3.9.18

Наименование

rabbitmq

vmware
Затронутые версииВерсия исправления

>= 3.8.0, <3.8.32

3.8.32

EPSS

Процентиль: 26%
0.00334
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 4 года назад

RabbitMQ is a multi-protocol messaging and streaming broker. In affected versions the shovel and federation plugins perform URI obfuscation in their worker (link) state. The encryption key used to encrypt the URI was seeded with a predictable secret. This means that in case of certain exceptions related to Shovel and Federation plugins, reasonably easily deobfuscatable data could appear in the node log. Patched versions correctly use a cluster-wide secret for that purpose. This issue has been addressed and Patched versions: `3.10.2`, `3.9.18`, `3.8.32` are available. Users unable to upgrade should disable the Shovel and Federation plugins.

CVSS3: 7.5
redhat
почти 4 года назад

RabbitMQ is a multi-protocol messaging and streaming broker. In affected versions the shovel and federation plugins perform URI obfuscation in their worker (link) state. The encryption key used to encrypt the URI was seeded with a predictable secret. This means that in case of certain exceptions related to Shovel and Federation plugins, reasonably easily deobfuscatable data could appear in the node log. Patched versions correctly use a cluster-wide secret for that purpose. This issue has been addressed and Patched versions: `3.10.2`, `3.9.18`, `3.8.32` are available. Users unable to upgrade should disable the Shovel and Federation plugins.

CVSS3: 5.5
nvd
почти 4 года назад

RabbitMQ is a multi-protocol messaging and streaming broker. In affected versions the shovel and federation plugins perform URI obfuscation in their worker (link) state. The encryption key used to encrypt the URI was seeded with a predictable secret. This means that in case of certain exceptions related to Shovel and Federation plugins, reasonably easily deobfuscatable data could appear in the node log. Patched versions correctly use a cluster-wide secret for that purpose. This issue has been addressed and Patched versions: `3.10.2`, `3.9.18`, `3.8.32` are available. Users unable to upgrade should disable the Shovel and Federation plugins.

CVSS3: 5.5
debian
почти 4 года назад

RabbitMQ is a multi-protocol messaging and streaming broker. In affect ...

suse-cvrf
больше 3 лет назад

Security update for rabbitmq-server

EPSS

Процентиль: 26%
0.00334
Низкий

5.5 Medium

CVSS3