Cleartext storage of sensitive information in RabbitMQ Server - #VU137244

 

Cleartext storage of sensitive information in RabbitMQ Server - #VU137244

Published: July 9, 2026


Vulnerability identifier: #VU137244
CSH Severity: Low
CVSS v4 BT: 4.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: N/A
CWE-ID: CWE-312
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to cleartext storage of sensitive information in the AMQP 1.0 shovel status output when exposing shovel status via the management API or command-line status command. A remote privileged user can read stored connection URIs containing embedded credentials to disclose sensitive information.

The issue affects AMQP 1.0 shovels configured with URI-embedded credentials, and exploitation requires access to read shovel status.


Affected software

RabbitMQ Server

Remediation

Install security update from vendor's website.

RabbitMQ Server - addressed in versions 3.13.15, 4.0.20, 4.1.11, 4.2.6

External References

Related Security Bulletins