Описание
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ does not perform authorization checks on passive queue.declare and exchange.declare AMQP 0-9-1 operations, allowing any authenticated user who can connect to a virtual host to enumerate queue and exchange names and read queue message and consumer counts. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.
A flaw was found in RabbitMQ. This vulnerability allows an authenticated user, with the ability to connect to a virtual host, to bypass authorization checks during passive queue.declare and exchange.declare AMQP 0-9-1 (Advanced Message Queuing Protocol) operations. This bypass enables the user to enumerate queue and exchange names, and read queue message and consumer counts, leading to information disclosure.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenStack Platform 16.2 | rabbitmq-server | Not affected | ||
| Red Hat OpenStack Platform 17.1 | rabbitmq-server | Not affected | ||
| Red Hat OpenStack Platform 18.0 | rabbitmq-server | Not affected | ||
| Red Hat Hardened Images | rabbitmq-server4-3-main-4.3.2-1.hum1 | Fixed | RHSA-2026:35939 | 06.07.2026 |
| Red Hat Hardened Images | rabbitmq-server4-2-main-4.2.8-1.hum1 | Fixed | RHSA-2026:35940 | 06.07.2026 |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
5 Medium
CVSS3
Связанные уязвимости
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ does not perform authorization checks on passive queue.declare and exchange.declare AMQP 0-9-1 operations, allowing any authenticated user who can connect to a virtual host to enumerate queue and exchange names and read queue message and consumer counts. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ does not perform authorization checks on passive queue.declare and exchange.declare AMQP 0-9-1 operations, allowing any authenticated user who can connect to a virtual host to enumerate queue and exchange names and read queue message and consumer counts. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20 ...
Passive queue/exchange declaration bypasses authorization checks, leaking queue metadata to unprivileged users
5 Medium
CVSS3