PT-2026-98893 · Vmware · Rabbitmq
CVE-2026-67236
·
Published
2026-09-25
·
Updated
2026-09-28
CVSS v4.0
8.2
High
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
RabbitMQ versions 4.2.0 through 4.2.7
RabbitMQ versions 4.3.0 through 4.3.1
Description
A successful request to the 'POST /login' endpoint causes the
is authorized/2 function to set an authentication cookie containing base64-encoded username and password credentials. This cookie lacks HttpOnly, Secure, SameSite, and expiration protections. Since base64 is an encoding method and not encryption, an attacker with same-origin cross-site scripting, an HTTP-readable network position, or local access to the browser cookie store could recover the plain-text login credentials. Additionally, older browsers that treat a missing SameSite attribute as None may send the cookie cross-site.Recommendations
Update to version 4.2.8.
Update to version 4.3.2.
Exploit
Fix
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rabbitmq