RabbitMQ是RabbitMQ开源的一个功能丰富的多协议消息和流媒体代理。 RabbitMQ 3.13.7及之前版本存在日志信息泄露漏洞,该漏洞源于日志中明文记录base64编码的授权标头。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| rabbitmq | rabbitmq-server | <= 3.13.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
VULNERABLE: Basic Auth username logged in HTTP access log: 127.0.0.1 - guest [31/May/2026:10:04:08 +0000] "GET /api/overview HTTP/1.1" 200 2647 "" "curl/8.5.0"
No comments yet