CyberRota Analysis
AI-GeneratedRabbitMQ versions from 3.13.0 to 4.3.3, including several prior releases, are vulnerable due to a flaw in the Federation upstream feature that bypasses virtual host (vhost) authorization, allowing a policymaker on one vhost to read and drain messages from another vhost without proper permissions. This can lead to unauthorized data access and loss, as the default acknowledgment mode results in the source messages being deleted rather than copied. Organizations using affected RabbitMQ versions, particularly those managing sensitive or multi-tenant environments, should prioritize upgrading to the patched versions to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
RabbitMQ is a messaging and streaming broker. From 3.13.0 until 4.3.3, 4.2.9 , 4.1.14, 4.0.24, and 3.13.18, Federation upstream in RabbitMQ skips vhost authorization allowing cross-vhost message access. what the bug lets you do. A policymaker on one vhost reads and drains messages out of another vhost it has no permission on. With the default ack-mode the source messages are consumed (deleted), not copied. Why that should not 1. Federation validates the upstream URI without any vhost-access Cross-vhost message read/drain from a per-vhost policymaker, breaking vhost tenancy This issue is fixed in versions 4.3.3, 4.2.9 , 4.1.14, 4.0.24, and 3.13.18.
Related CVEs
Other vulnerabilities affecting the same vendor(s)