Back to Vulnerability Directory
HIGHFixed upstream

CVE-2016-0929

metrics-collection component in RabbitMQ for Pivotal Cloud Foundry (PCF) 1.6.x before 1.6.4 logs…

Technology

RabbitMQ

CVSS Score

7.5 / 10.0

Affected Versions

1.6.0; 1.6.1; 1.6.2; 1.6.3

Upstream Fix

See upstream advisory

Published

September 18, 2016

OSSeva Coverage

Fixed upstream

Description

The metrics-collection component in RabbitMQ for Pivotal Cloud Foundry (PCF) 1.6.x before 1.6.4 logs command lines of failed commands, which might allow context-dependent attackers to obtain sensitive information by reading the log data, as demonstrated by a syslog message that contains credentials from a command line.

Is your RabbitMQ deployment affected?

If you're running 1.6.0; 1.6.1; 1.6.2; 1.6.3, you need this patch. Book a discovery call to get covered.