漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
RabbitMQ: Passive queue/exchange declaration bypasses authorization checks, leaking queue metadata to unprivileged users
Vulnerability Description
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ does not perform authorization checks on passive queue.declare and exchange.declare AMQP 0-9-1 operations, allowing any authenticated user who can connect to a virtual host to enumerate queue and exchange names and read queue message and consumer counts. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
Vulnerability Type
授权机制缺失
Vulnerability Title
rabbitmq rabbitmq-server 授权问题漏洞
Vulnerability Description
RabbitMQ rabbitmq-server是RabbitMQ组织的消息队列中间件。 RabbitMQ rabbitmq-server存在授权问题漏洞,该漏洞源于未对被动queue.declare和exchange.declare AMQP 0-9-1操作执行授权检查,允许任何能连接到虚拟主机的已认证用户枚举队列和交换器名称,并读取队列消息和消费者计数。以下版本受到影响:3.13.15之前版本、4.0.20之前版本、4.1.11之前版本和4.2.6之前版本。
CVSS Information
N/A
Vulnerability Type
N/A