CVE-2023-35789: Medium severity Rabbitmq-c Project Rabbitmq-c vulnerability
An issue was discovered in the C AMQP client library (aka rabbitmq-c) through 0.13.0 for RabbitMQ. Credentials can only be entered on the command line (e.g., for amqp-publish or amqp-consume) and are thus visible to local attackers by listing a process and its arguments.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/librabbitmqto a version that resolves this vulnerability.Fixed in 0.11.0-1+deb12u2Fixed in 0.11.0-1+deb12u3Fixed in 0.15.0-1+deb13u1Fixed in 0.15.0-1+deb13u2Fixed in 0.17.0-1
Event History
Frequently Asked Questions
What is the severity of CVE-2023-35789?
CVE-2023-35789 is classified as a medium severity issue due to the exposure of sensitive data.
How do I fix CVE-2023-35789?
To mitigate CVE-2023-35789, upgrade to a version of rabbitmq-c greater than 0.13.0 where the issue is resolved.
What systems are affected by CVE-2023-35789?
CVE-2023-35789 affects the rabbitmq-c C AMQP client library up to version 0.13.0.
What are the potential risks of CVE-2023-35789?
The primary risk associated with CVE-2023-35789 is the potential exposure of credentials to local attackers through command line arguments.
Can CVE-2023-35789 be exploited remotely?
CVE-2023-35789 cannot be exploited remotely as it requires local access to execute commands with visible arguments.