Executive brief
RabbitMQ, a widely used message broker, contains a vulnerability in its Shovel and Federation plugins where sensitive connection details are protected by a predictable encryption key. If the system encounters an error, these partially protected credentials may be written to system logs in a format that is easy for an unauthorized user to decode. This could allow a local attacker with access to the logs to obtain credentials for other connected systems.
Technical details
The Shovel and Federation plugins in RabbitMQ perform URI obfuscation in their worker state to protect sensitive connection strings. However, the encryption key used for this obfuscation was seeded with a predictable secret rather than a cryptographically strong, unique value. In the event of certain exceptions, these obfuscated URIs are written to the RabbitMQ node logs. Because the seed is predictable, a local attacker with read access to the logs can de-obfuscate the data to recover plaintext credentials. The fix introduces the use of a cluster-wide secret for the obfuscation seed and ensures it is initialized earlier in the boot process.
Affected products
- RabbitMQ RabbitMQ >= 3.10.0, < 3.10.2; >= 3.9.0, < 3.9.18; >= 3.8.0, < 3.8.32
Timeline
- 2022-05-19: patched: Fix merged into master branch
- 2022-10-05: advisory: GitHub Advisory published
- 2022-10-06: disclosed: NVD publication date
References
- https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-v9gv-xp36-jgj8
- https://github.com/rabbitmq/rabbitmq-server/pull/4841
- https://github.com/rabbitmq/rabbitmq-server/commit/c22e1cb20e656d211e025c417d1fc75a9067b717
- https://api.github.com/repos/rabbitmq/rabbitmq-server/security-advisories/GHSA-v9gv-xp36-jgj8