CVE-2025-50200
- EPSS 0.02%
- Veröffentlicht 19.06.2025 16:14:24
- Zuletzt bearbeitet 06.08.2025 18:28:43
RabbitMQ is a messaging and streaming broker. In versions 3.13.7 and prior, RabbitMQ is logging authorization headers in plaintext encoded in base64. When querying RabbitMQ api with HTTP/s with basic authentication it creates logs with all headers in...
CVE-2022-31008
- EPSS 0.09%
- Veröffentlicht 06.10.2022 18:16:00
- Zuletzt bearbeitet 02.04.2025 14:13:43
RabbitMQ is a multi-protocol messaging and streaming broker. In affected versions the shovel and federation plugins perform URI obfuscation in their worker (link) state. The encryption key used to encrypt the URI was seeded with a predictable secret....
CVE-2021-22117
- EPSS 0.12%
- Veröffentlicht 18.05.2021 13:15:07
- Zuletzt bearbeitet 02.04.2025 14:13:43
RabbitMQ installers on Windows prior to version 3.8.16 do not harden plugin directory permissions, potentially allowing attackers with sufficient local filesystem permissions to add arbitrary plugins.
CVE-2020-5419
- EPSS 0.07%
- Veröffentlicht 31.08.2020 15:15:11
- Zuletzt bearbeitet 02.04.2025 14:13:43
RabbitMQ versions 3.8.x prior to 3.8.7 are prone to a Windows-specific binary planting security vulnerability that allows for arbitrary code execution. An attacker with write privileges to the RabbitMQ installation directory and local access on Windo...
CVE-2019-11287
- EPSS 0.79%
- Veröffentlicht 23.11.2019 00:15:10
- Zuletzt bearbeitet 02.04.2025 14:13:43
Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is vulnerable to a denial of servi...
CVE-2019-11291
- EPSS 0.48%
- Veröffentlicht 22.11.2019 23:15:11
- Zuletzt bearbeitet 02.04.2025 14:13:43
Pivotal RabbitMQ, 3.7 versions prior to v3.7.20 and 3.8 version prior to v3.8.1, and RabbitMQ for PCF, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain two endpoints, federation and shovel, which do not properly sanitize u...
CVE-2017-4965
- EPSS 0.83%
- Veröffentlicht 13.06.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to 1.6.18, and 1.7.x versions prior t...
CVE-2017-4966
- EPSS 0.09%
- Veröffentlicht 13.06.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to 1.6.18, and 1.7.x versions prior t...
CVE-2017-4967
- EPSS 0.6%
- Veröffentlicht 13.06.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to 1.6.18, and 1.7.x versions prior t...
CVE-2016-9877
- EPSS 0.33%
- Veröffentlicht 29.12.2016 09:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
An issue was discovered in Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before 3.6.6 and RabbitMQ for PCF 1.5.x before 1.5.20, 1.6.x before 1.6.12, and 1.7.x before 1.7.7. MQTT (MQ Telemetry Transport) connection authentication with a username/passwor...