First published: Fri Jun 16 2023(Updated: )
An issue was discovered in the C AMQP client library (aka rabbitmq-c) through 0.13.0 for RabbitMQ. Credentials can only be entered on the command line (e.g., for amqp-publish or amqp-consume) and are thus visible to local attackers by listing a process and its arguments.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
RabbitMQ | <=0.13.0 | |
<=0.13.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-35789 is classified as a medium severity issue due to the exposure of sensitive data.
To mitigate CVE-2023-35789, upgrade to a version of rabbitmq-c greater than 0.13.0 where the issue is resolved.
CVE-2023-35789 affects the rabbitmq-c C AMQP client library up to version 0.13.0.
The primary risk associated with CVE-2023-35789 is the potential exposure of credentials to local attackers through command line arguments.
CVE-2023-35789 cannot be exploited remotely as it requires local access to execute commands with visible arguments.