First published: Sun Sep 18 2016(Updated: )
The metrics-collection component in RabbitMQ for Pivotal Cloud Foundry (PCF) 1.6.x before 1.6.4 logs command lines of failed commands, which might allow context-dependent attackers to obtain sensitive information by reading the log data, as demonstrated by a syslog message that contains credentials from a command line.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pivotal Software Rabbitmq | =1.6.0 | |
Pivotal Software Rabbitmq | =1.6.1 | |
Pivotal Software Rabbitmq | =1.6.2 | |
Pivotal Software Rabbitmq | =1.6.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.