CyberRota Analysis
AI-GeneratedRabbitMQ versions prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6 are vulnerable to a flaw that allows loopback-restricted users, such as the guest account, to connect remotely when traffic is routed through a trusted PROXY-protocol path. This vulnerability arises from the improper handling of loopback checks, potentially exposing sensitive messaging and streaming data to unauthorized access. Organizations using affected versions should prioritize updating to the fixed releases to mitigate the risk of unauthorized remote access.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, AMQP 0-9-1, AMQP 1.0, and Stream Protocol authentication can allow a loopback-restricted user such as guest to connect remotely when traffic is accepted through a trusted PROXY-protocol path and the backend listener is loopback-bound because the loopback check uses the listener-side socket address instead of the real client source. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.
Related CVEs
Other vulnerabilities affecting the same vendor(s)