Cleartext storage of sensitive information in RabbitMQ Server - #VU137244
Published: July 9, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to cleartext storage of sensitive information in the AMQP 1.0 shovel status output when exposing shovel status via the management API or command-line status command. A remote privileged user can read stored connection URIs containing embedded credentials to disclose sensitive information.
The issue affects AMQP 1.0 shovels configured with URI-embedded credentials, and exploitation requires access to read shovel status.