Back to Vulnerability Directory
HIGHFixed upstream

CVE-2022-31008

RabbitMQ Shovel and Federation obfuscate URIs with a predictable key

Technology

RabbitMQ

CVSS Score

7.5 / 10.0

Affected Versions

3.8.0 to 3.8.31; 3.9.0 to 3.9.17; 3.10.0 to 3.10.1

Upstream Fix

3.8.32; 3.9.18; 3.10.2

Published

October 6, 2022

OSSeva Coverage

Fixed upstream

Description

The Shovel and Federation plugins obfuscate connection URIs in their link state, but the key used to encrypt them was seeded with a predictable secret. After certain Shovel or Federation exceptions, easily deobfuscated URIs, including credentials, could appear in the node log. Fixed releases use a cluster-wide secret. NVD scores it 7.5; GitHub, as the CNA, scores it 5.5. Disabling the Shovel and Federation plugins avoids it.

Upstream record: NVD · CVE.org

Is your RabbitMQ deployment affected?

If you're running 3.8.0 to 3.8.31; 3.9.0 to 3.9.17; 3.10.0 to 3.10.1, you need this patch. Book a discovery call to get covered.