PT-2016-4482 · Pivotal+1 · Rabbitmq

Published

2016-09-18

·

Updated

2016-11-28

·

CVE-2016-0929

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions RabbitMQ for Pivotal Cloud Foundry (PCF) versions 1.6.x through 1.6.3
Description The issue allows context-dependent attackers to obtain sensitive information by reading the log data. This is because the metrics-collection component logs command lines of failed commands, which might include sensitive information such as credentials. For example, a syslog message could contain credentials from a command line.
Recommendations For RabbitMQ for Pivotal Cloud Foundry (PCF) versions 1.6.x through 1.6.3, update to version 1.6.4 or later to resolve the issue. As a temporary workaround, consider restricting access to log data to minimize the risk of sensitive information disclosure.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-0929

Affected Products

Rabbitmq