PT-2026-105052 · Azure Linux · Rabbitmq-Server

Publicado

2026-09-23

·

Atualizado

2026-09-23

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, Neither the Web-MQTT handler (deps/rabbitmq web mqtt/src/rabbit web mqtt handler.erl:104) nor the Web-STOMP handler (deps/rabbitmq web stomp/src/rabbit web stomp handler.erl:102) validates the Origin header on the WebSocket upgrade. Under ssl cert login=true, the browser presents the client certificate automatically, so an attacker's JavaScript running in the victim's browser can authenticate as the victim. Preconditions include The non-default configuration use http auth=true (Web-STOMP) or ssl cert login=true (both plugins) must be enabled. The issue is harmless under the default in-band CONNECT credential configuration.. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

AZL-105747

Produtos afetados

Rabbitmq-Server