Back to Vulnerability Directory
HIGHFixed upstream
CVE-2016-0929
metrics-collection component in RabbitMQ for Pivotal Cloud Foundry (PCF) 1.6.x before 1.6.4 logs…
Technology
RabbitMQ
CVSS Score
7.5 / 10.0
Affected Versions
1.6.0; 1.6.1; 1.6.2; 1.6.3
Upstream Fix
See upstream advisory
Published
September 18, 2016
OSSeva Coverage
Fixed upstream
Description
The metrics-collection component in RabbitMQ for Pivotal Cloud Foundry (PCF) 1.6.x before 1.6.4 logs command lines of failed commands, which might allow context-dependent attackers to obtain sensitive information by reading the log data, as demonstrated by a syslog message that contains credentials from a command line.
Is your RabbitMQ deployment affected?
If you're running 1.6.0; 1.6.1; 1.6.2; 1.6.3, you need this patch. Book a discovery call to get covered.