CVE-2022-31008
RabbitMQ Shovel and Federation obfuscate URIs with a predictable key
Technology
RabbitMQ
CVSS Score
7.5 / 10.0
Affected Versions
3.8.0 to 3.8.31; 3.9.0 to 3.9.17; 3.10.0 to 3.10.1
Upstream Fix
3.8.32; 3.9.18; 3.10.2
Published
October 6, 2022
OSSeva Coverage
Fixed upstream
Description
The Shovel and Federation plugins obfuscate connection URIs in their link state, but the key used to encrypt them was seeded with a predictable secret. After certain Shovel or Federation exceptions, easily deobfuscated URIs, including credentials, could appear in the node log. Fixed releases use a cluster-wide secret. NVD scores it 7.5; GitHub, as the CNA, scores it 5.5. Disabling the Shovel and Federation plugins avoids it.
Is your RabbitMQ deployment affected?
If you're running 3.8.0 to 3.8.31; 3.9.0 to 3.9.17; 3.10.0 to 3.10.1, you need this patch. Book a discovery call to get covered.