Описание
RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, RabbitMQ AMQP 0-9-1 allows an existing consumer to keep receiving messages after OAuth token expiry or connection.update_secret refresh to reduced scopes because existing consumers are not canceled or reauthorized at delivery time after the channel user state changes. This issue is fixed in version 4.2.6.
A flaw was found in RabbitMQ. An existing consumer in RabbitMQ AMQP 0-9-1 can continue to receive messages even after its OAuth token has expired or its connection's scopes have been reduced. This occurs because consumers are not properly canceled or reauthorized when the channel user state changes, potentially leading to unauthorized information disclosure.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenStack Platform 16.2 | rabbitmq-server | Not affected | ||
| Red Hat OpenStack Platform 17.1 | rabbitmq-server | Not affected | ||
| Red Hat OpenStack Platform 18.0 | rabbitmq-server | Not affected | ||
| Red Hat Hardened Images | rabbitmq-server4-3-main-4.3.2-1.hum1 | Fixed | RHSA-2026:35939 | 06.07.2026 |
| Red Hat Hardened Images | rabbitmq-server4-2-main-4.2.8-1.hum1 | Fixed | RHSA-2026:35940 | 06.07.2026 |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
6.5 Medium
CVSS3
Связанные уязвимости
RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, RabbitMQ AMQP 0-9-1 allows an existing consumer to keep receiving messages after OAuth token expiry or connection.update_secret refresh to reduced scopes because existing consumers are not canceled or reauthorized at delivery time after the channel user state changes. This issue is fixed in version 4.2.6.
RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, RabbitMQ AMQP 0-9-1 allows an existing consumer to keep receiving messages after OAuth token expiry or connection.update_secret refresh to reduced scopes because existing consumers are not canceled or reauthorized at delivery time after the channel user state changes. This issue is fixed in version 4.2.6.
RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, RabbitMQ ...
AMQP 0-9-1 in combination with OAuth 2: consumer persistence can lead to post-revocation message disclosure
6.5 Medium
CVSS3