CVE-2016-0929: Infoleak
The metrics-collection component in RabbitMQ for Pivotal Cloud Foundry (PCF) 1.6.x before 1.6.4 logs command lines of failed commands, which might allow context-dependent attackers to obtain sensitive information by reading the log data, as demonstrated by a syslog message that contains credentials from a command line.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0929?
CVE-2016-0929 has a Medium severity rating due to its potential exposure of sensitive information through logs.
How do I fix CVE-2016-0929?
To fix CVE-2016-0929, upgrade RabbitMQ for Pivotal Cloud Foundry to version 1.6.4 or later.
What are the affected versions of RabbitMQ in CVE-2016-0929?
CVE-2016-0929 affects RabbitMQ versions 1.6.0 through 1.6.3.
What type of information can be exposed by CVE-2016-0929?
CVE-2016-0929 may expose sensitive information including credentials through the logging of failed command lines.
Who can exploit CVE-2016-0929?
CVE-2016-0929 can potentially be exploited by context-dependent attackers with access to the log data.