PT-2026-46260 · Openstack+1 · Oslo.Messaging+1
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
oslo.messaging versions 1.0.0 through 17.3.0
Description
The RabbitMQ driver in oslo.messaging fails to perform TLS hostname verification when connecting to the message broker. While the driver enables certificate chain validation when
ssl ca file is configured, it does not pass the expected broker hostname to the TLS stack. Consequently, any certificate signed by the deployment CA is accepted regardless of the hostname. This allows an attacker capable of intercepting control-plane traffic to impersonate the RabbitMQ broker and execute a man-in-the-middle attack on RPC and notification traffic. All OpenStack services utilizing oslo.messaging with RabbitMQ over TLS are impacted.Recommendations
Update to version 18.1.0-1.1 or later.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rabbitmq
Oslo.Messaging