Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-66069

Опубликовано: 23 сент. 2026
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

RabbitMQ is a messaging and streaming broker. Prior to versions 4.1.13, 4.2.7, and 4.3.0, is_authorized/2 uses is_authorized_monitor for all methods. DELETE resets rabbit_core_metrics:reset_auth_attempt_metrics(). Impact is cosmetic (counters only, no log erasure), but inconsistent with rabbit_mgmt_wm_reset.erl which requires admin for the analogous operation. A monitoring-tagged user can reset the per-node authentication-attempt counters via DELETE /api/auth/attempts/:node, erasing evidence of brute-force activity. The sibling endpoint wm_reset requires administrator. Preconditions include Management plugin enabled monitoring tag. This issue is fixed in versions 4.1.13, 4.2.7, and 4.3.0.

A flaw was found in RabbitMQ. A user with a monitoring tag, when the Management plugin is enabled, can reset the per-node authentication-attempt counters. This action, which should be restricted to administrators, allows the monitoring-tagged user to erase evidence of brute-force login attempts. While the impact is primarily cosmetic, it creates an inconsistency in access control for a sensitive operation.

Отчет

Red Hat rates this flaw MODERATE in products that ship affected RabbitMQ builds. A monitoring-tagged user can reset authentication-attempt counters through the Management API without administrator permission. Broker logs remain intact, so the impact is limited to tampering with security metrics.

Меры по смягчению последствий

Restrict Management API access and monitoring-tag accounts, or disable the Management plugin where it is not needed.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Hardened Imagesrabbitmq-server4.2Will not fix
Red Hat OpenStack Platform 13 (Queens)rabbitmq-serverNot affected
Red Hat OpenStack Platform 16.2rabbitmq-serverNot affected
Red Hat OpenStack Platform 17.1rabbitmq-serverNot affected
Red Hat OpenStack Platform 18.0rabbitmq-serverFix deferred
Red Hat Hardened Imagesrabbitmq-server4-3-main-4.3.6-1.hum1FixedRHSA-2026:6755215.09.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-862
https://bugzilla.redhat.com/show_bug.cgi?id=2539756rabbitmq-server: RabbitMQ: Monitoring user can reset authentication attempt counters

EPSS

Процентиль: 31%
0.00395
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

ubuntu
10 дней назад

RabbitMQ is a messaging and streaming broker. Prior to versions 4.1.13, 4.2.7, and 4.3.0, is_authorized/2 uses is_authorized_monitor for all methods. DELETE resets rabbit_core_metrics:reset_auth_attempt_metrics(). Impact is cosmetic (counters only, no log erasure), but inconsistent with rabbit_mgmt_wm_reset.erl which requires admin for the analogous operation. A monitoring-tagged user can reset the per-node authentication-attempt counters via DELETE /api/auth/attempts/:node, erasing evidence of brute-force activity. The sibling endpoint wm_reset requires administrator. Preconditions include Management plugin enabled monitoring tag. This issue is fixed in versions 4.1.13, 4.2.7, and 4.3.0.

nvd
10 дней назад

RabbitMQ is a messaging and streaming broker. Prior to versions 4.1.13, 4.2.7, and 4.3.0, is_authorized/2 uses is_authorized_monitor for all methods. DELETE resets rabbit_core_metrics:reset_auth_attempt_metrics(). Impact is cosmetic (counters only, no log erasure), but inconsistent with rabbit_mgmt_wm_reset.erl which requires admin for the analogous operation. A monitoring-tagged user can reset the per-node authentication-attempt counters via DELETE /api/auth/attempts/:node, erasing evidence of brute-force activity. The sibling endpoint wm_reset requires administrator. Preconditions include Management plugin enabled monitoring tag. This issue is fixed in versions 4.1.13, 4.2.7, and 4.3.0.

debian
10 дней назад

RabbitMQ is a messaging and streaming broker. Prior to versions 4.1.13 ...

github
3 месяца назад

Monitoring-tag DELETE of auth-attempt metrics

EPSS

Процентиль: 31%
0.00395
Низкий

4.3 Medium

CVSS3