Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-31008

Опубликовано: 06 окт. 2022
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 5.5

Описание

RabbitMQ is a multi-protocol messaging and streaming broker. In affected versions the shovel and federation plugins perform URI obfuscation in their worker (link) state. The encryption key used to encrypt the URI was seeded with a predictable secret. This means that in case of certain exceptions related to Shovel and Federation plugins, reasonably easily deobfuscatable data could appear in the node log. Patched versions correctly use a cluster-wide secret for that purpose. This issue has been addressed and Patched versions: 3.10.2, 3.9.18, 3.8.32 are available. Users unable to upgrade should disable the Shovel and Federation plugins.

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-apps/jammy

needs-triage

esm-infra/focal

DNE

focal

DNE

jammy

needs-triage

kinetic

ignored

end of life, was needs-triage
lunar

ignored

end of life, was needs-triage
mantic

ignored

end of life, was needs-triage
noble

DNE

Показывать по

EPSS

Процентиль: 40%
0.00179
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
больше 3 лет назад

RabbitMQ is a multi-protocol messaging and streaming broker. In affected versions the shovel and federation plugins perform URI obfuscation in their worker (link) state. The encryption key used to encrypt the URI was seeded with a predictable secret. This means that in case of certain exceptions related to Shovel and Federation plugins, reasonably easily deobfuscatable data could appear in the node log. Patched versions correctly use a cluster-wide secret for that purpose. This issue has been addressed and Patched versions: `3.10.2`, `3.9.18`, `3.8.32` are available. Users unable to upgrade should disable the Shovel and Federation plugins.

CVSS3: 5.5
nvd
больше 3 лет назад

RabbitMQ is a multi-protocol messaging and streaming broker. In affected versions the shovel and federation plugins perform URI obfuscation in their worker (link) state. The encryption key used to encrypt the URI was seeded with a predictable secret. This means that in case of certain exceptions related to Shovel and Federation plugins, reasonably easily deobfuscatable data could appear in the node log. Patched versions correctly use a cluster-wide secret for that purpose. This issue has been addressed and Patched versions: `3.10.2`, `3.9.18`, `3.8.32` are available. Users unable to upgrade should disable the Shovel and Federation plugins.

CVSS3: 5.5
debian
больше 3 лет назад

RabbitMQ is a multi-protocol messaging and streaming broker. In affect ...

suse-cvrf
около 3 лет назад

Security update for rabbitmq-server

suse-cvrf
больше 1 года назад

Feature update for rabbitmq-server313, erlang26, elixir115

EPSS

Процентиль: 40%
0.00179
Низкий

5.5 Medium

CVSS3