### Impact Shovel and Federation plugins perform URI obfuscation in their worker (link) state. The encryption key used to encrypt the URI was seeded with a predictable secret. This means that in case of certain exceptions related to Shovel and Federation plugins, reasonably easily deobfuscatable data could appear in the node log. Patched versions correctly use a cluster-wide secret for that purpose. ### Patches Patched versions: * `3.10.2` * `3.9.18` * `3.8.32` ### Workarounds Disable Shovel and Federation plugins. ### Credits RabbitMQ core team would like to thank Lajos @luos Gerecs and Anh Nguyen from Erlang Solutions for responsibly disclosing and working with us on a patch for this vulnerability. ### For more information * [Mailing list](https://groups.google.com/forum/#!forum/rabbitmq-users) * [Community Slack](https://rabbitmq-slack.herokuapp.com/)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free