Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 7

Количество 7

github логотип

GHSA-v9gv-xp36-jgj8

почти 4 года назад

Predictable credential obfuscation seed value used in Shovel and Federation plugins

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2022-31008

почти 4 года назад

RabbitMQ is a multi-protocol messaging and streaming broker. In affected versions the shovel and federation plugins perform URI obfuscation in their worker (link) state. The encryption key used to encrypt the URI was seeded with a predictable secret. This means that in case of certain exceptions related to Shovel and Federation plugins, reasonably easily deobfuscatable data could appear in the node log. Patched versions correctly use a cluster-wide secret for that purpose. This issue has been addressed and Patched versions: `3.10.2`, `3.9.18`, `3.8.32` are available. Users unable to upgrade should disable the Shovel and Federation plugins.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2022-31008

почти 4 года назад

RabbitMQ is a multi-protocol messaging and streaming broker. In affected versions the shovel and federation plugins perform URI obfuscation in their worker (link) state. The encryption key used to encrypt the URI was seeded with a predictable secret. This means that in case of certain exceptions related to Shovel and Federation plugins, reasonably easily deobfuscatable data could appear in the node log. Patched versions correctly use a cluster-wide secret for that purpose. This issue has been addressed and Patched versions: `3.10.2`, `3.9.18`, `3.8.32` are available. Users unable to upgrade should disable the Shovel and Federation plugins.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2022-31008

почти 4 года назад

RabbitMQ is a multi-protocol messaging and streaming broker. In affected versions the shovel and federation plugins perform URI obfuscation in their worker (link) state. The encryption key used to encrypt the URI was seeded with a predictable secret. This means that in case of certain exceptions related to Shovel and Federation plugins, reasonably easily deobfuscatable data could appear in the node log. Patched versions correctly use a cluster-wide secret for that purpose. This issue has been addressed and Patched versions: `3.10.2`, `3.9.18`, `3.8.32` are available. Users unable to upgrade should disable the Shovel and Federation plugins.

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2022-31008

почти 4 года назад

RabbitMQ is a multi-protocol messaging and streaming broker. In affect ...

CVSS3: 5.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:4378-1

больше 3 лет назад

Security update for rabbitmq-server

EPSS: Низкий
suse-cvrf логотип

SUSE-FU-2024:2078-1

около 2 лет назад

Feature update for rabbitmq-server313, erlang26, elixir115

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-v9gv-xp36-jgj8

Predictable credential obfuscation seed value used in Shovel and Federation plugins

CVSS3: 5.5
0%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-31008

RabbitMQ is a multi-protocol messaging and streaming broker. In affected versions the shovel and federation plugins perform URI obfuscation in their worker (link) state. The encryption key used to encrypt the URI was seeded with a predictable secret. This means that in case of certain exceptions related to Shovel and Federation plugins, reasonably easily deobfuscatable data could appear in the node log. Patched versions correctly use a cluster-wide secret for that purpose. This issue has been addressed and Patched versions: `3.10.2`, `3.9.18`, `3.8.32` are available. Users unable to upgrade should disable the Shovel and Federation plugins.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-31008

RabbitMQ is a multi-protocol messaging and streaming broker. In affected versions the shovel and federation plugins perform URI obfuscation in their worker (link) state. The encryption key used to encrypt the URI was seeded with a predictable secret. This means that in case of certain exceptions related to Shovel and Federation plugins, reasonably easily deobfuscatable data could appear in the node log. Patched versions correctly use a cluster-wide secret for that purpose. This issue has been addressed and Patched versions: `3.10.2`, `3.9.18`, `3.8.32` are available. Users unable to upgrade should disable the Shovel and Federation plugins.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-31008

RabbitMQ is a multi-protocol messaging and streaming broker. In affected versions the shovel and federation plugins perform URI obfuscation in their worker (link) state. The encryption key used to encrypt the URI was seeded with a predictable secret. This means that in case of certain exceptions related to Shovel and Federation plugins, reasonably easily deobfuscatable data could appear in the node log. Patched versions correctly use a cluster-wide secret for that purpose. This issue has been addressed and Patched versions: `3.10.2`, `3.9.18`, `3.8.32` are available. Users unable to upgrade should disable the Shovel and Federation plugins.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-31008

RabbitMQ is a multi-protocol messaging and streaming broker. In affect ...

CVSS3: 5.5
0%
Низкий
почти 4 года назад
suse-cvrf логотип
SUSE-SU-2022:4378-1

Security update for rabbitmq-server

0%
Низкий
больше 3 лет назад
suse-cvrf логотип
SUSE-FU-2024:2078-1

Feature update for rabbitmq-server313, erlang26, elixir115

около 2 лет назад

Уязвимостей на страницу