PT-2026-105050 · Azure Linux · Rabbitmq-Server

Published

2026-09-23

·

Updated

2026-09-23

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, The AMQP 0-9-1 shovel calls amqp uri:remove credentials before storing its connection URI, but the AMQP 1.0 shovel stores the raw URI including the password. The stored URI is visible via GET /api/shovels and via rabbitmqctl shovel status. Preconditions include The Shovel plugin must be in use with AMQP 1.0 shovels configured using URI-embedded credentials. Reading the exposed status requires the monitoring tag.. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-105738

Affected Products

Rabbitmq-Server