Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-66070

Опубликовано: 23 сент. 2026
Источник: redhat
CVSS3: 8.1

Описание

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.17, 4.0.22, 4.1.13, and 4.2.6, match_origin/1 returned the bare reflected Origin and allowed credentials even when the wildcard "" was configured, so the response echoed the attacker's origin together with Access-Control-Allow-Credentials. The affected code is rabbit_mgmt_cors.erl. When the management plugin is configured with a wildcard CORS origin (cors_allow_origins = ""), the handler reflects the request Origin back in Access-Control-Allow-Origin and also sends Access-Control-Allow-Credentials: true. A malicious web page that a signed-in administrator visits can then use that administrator's cached HTTP Basic credentials to issue authenticated, state-changing requests to the management API. Preconditions include The management plugin is configured with the wildcard cors_allow_origins = "*", which is an explicit operator misconfiguration A target administrator has a cached HTTP Basic-auth session in the browser. This issue is fixed in versions 3.13.17, 4.0.22, 4.1.13, and 4.2.6.

A flaw was found in RabbitMQ. When the management plugin is configured with a wildcard Cross-Origin Resource Sharing (CORS) origin, it incorrectly reflects the attacker's origin and allows credentials. This vulnerability enables a malicious web page to leverage a signed-in administrator's cached credentials. Consequently, an attacker can issue authenticated requests to the management API, potentially leading to unauthorized actions.

Отчет

Red Hat rates this flaw IMPORTANT in products that ship affected RabbitMQ builds. If the Management plugin allows wildcard CORS and an administrator has cached HTTP Basic credentials, a malicious website visited by that administrator can make authenticated Management API requests, potentially exposing sensitive information or changing broker configuration.

Меры по смягчению последствий

Replace wildcard CORS with explicit trusted origins and avoid administrator Basic credentials in browsers used for untrusted sites.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Hardened Imagesrabbitmq-server4.2Will not fix
Red Hat OpenStack Platform 13 (Queens)rabbitmq-serverNot affected
Red Hat OpenStack Platform 16.2rabbitmq-serverNot affected
Red Hat OpenStack Platform 17.1rabbitmq-serverNot affected
Red Hat OpenStack Platform 18.0rabbitmq-serverNot affected
Red Hat Hardened Imagesrabbitmq-server4-3-main-4.3.6-1.hum1FixedRHSA-2026:6755215.09.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-942
https://bugzilla.redhat.com/show_bug.cgi?id=2539724rabbitmq-server: RabbitMQ: Cross-Origin Resource Sharing (CORS) misconfiguration allows unauthorized actions

8.1 High

CVSS3

Связанные уязвимости

ubuntu
10 дней назад

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.17, 4.0.22, 4.1.13, and 4.2.6, match_origin/1 returned the bare reflected Origin and allowed credentials even when the wildcard "" was configured, so the response echoed the attacker's origin together with Access-Control-Allow-Credentials. The affected code is rabbit_mgmt_cors.erl. When the management plugin is configured with a wildcard CORS origin (cors_allow_origins = ""), the handler reflects the request Origin back in Access-Control-Allow-Origin and also sends Access-Control-Allow-Credentials: true. A malicious web page that a signed-in administrator visits can then use that administrator's cached HTTP Basic credentials to issue authenticated, state-changing requests to the management API. Preconditions include The management plugin is configured with the wildcard cors_allow_origins = "*", which is an explicit operator misconfiguration A target administrator has a cached HTTP Basic-auth session in the browser....

nvd
10 дней назад

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.17, 4.0.22, 4.1.13, and 4.2.6, match_origin/1 returned the bare reflected Origin and allowed credentials even when the wildcard "" was configured, so the response echoed the attacker's origin together with Access-Control-Allow-Credentials. The affected code is rabbit_mgmt_cors.erl. When the management plugin is configured with a wildcard CORS origin (cors_allow_origins = ""), the handler reflects the request Origin back in Access-Control-Allow-Origin and also sends Access-Control-Allow-Credentials: true. A malicious web page that a signed-in administrator visits can then use that administrator's cached HTTP Basic credentials to issue authenticated, state-changing requests to the management API. Preconditions include The management plugin is configured with the wildcard cors_allow_origins = "*", which is an explicit operator misconfiguration A target administrator has a cached HTTP Basic-auth session in the browser. Th

msrc
около 13 часов назад

RabbitMQ: CORS * reflects Origin with Allow-Credentials

debian
10 дней назад

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.1 ...

github
3 месяца назад

CORS * reflects Origin with Allow-Credentials

8.1 High

CVSS3