[Debian] Medium CVE: CVE-2023-35789 librabbitmq: local attackers by listing a process and its arguments
Bug #2105457 reported by
Yue Tao
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
StarlingX |
Fix Released
|
High
|
Unassigned |
Bug Description
CVE-2023-35789: https:/
An issue was discovered in the C AMQP client library (aka rabbitmq-c) through 0.13.0 for RabbitMQ. Credentials can only be entered on the command line (e.g., for amqp-publish or amqp-consume) and are thus visible to local attackers by listing a process and its arguments.
Base Score: Medium
Reference:
['librabbitmq4_
https:/
CVE References
To post a comment you must log in.
Fix proposed to branch: master /review. opendev. org/c/starlingx /tools/ +/950319
Review: https:/