PT-2026-97589 · Vmware · Rabbitmq
CVE-2026-67221
·
Published
2026-09-23
·
Updated
2026-09-24
CVSS v4.0
5.9
Medium
| Vector | AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
RabbitMQ versions prior to 3.13.15
RabbitMQ versions prior to 4.0.20
RabbitMQ versions prior to 4.1.11
RabbitMQ versions prior to 4.2.6
RabbitMQ versions prior to 4.3.0
Description
The AMQP 1.0 shovel stores the raw connection URI including the password, whereas the AMQP 0-9-1 shovel removes credentials before storage. This allows the password to be exposed via the
GET /api/shovels endpoint and the rabbitmqctl shovel status command. This occurs when the Shovel plugin is used with AMQP 1.0 shovels configured with URI-embedded credentials. Accessing the exposed status requires the monitoring tag.Recommendations
Update to version 3.13.15.
Update to version 4.0.20.
Update to version 4.1.11.
Update to version 4.2.6.
Update to version 4.3.0.
Exploit
Fix
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rabbitmq