Aller au contenu

Fiche vulnérabilité

CVE-2026-57221 : faille moyenne broadcom rabbitmq server (CVSS 5.0)

Description

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ does not perform authorization checks on passive queue.declare and exchange.declare AMQP 0-9-1 operations, allowing any authenticated user who can connect to a virtual host to enumerate queue and exchange names and read queue message and consumer counts. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.

En bref

Sévérité
Moyenne (CVSS 5.0)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Exploitation active
Non signalée par la CISA
Publication
10 juil. 2026
Dernière mise à jour
13 juil. 2026

Produits concernés

  • broadcom rabbitmq server

Références

Rechercher une autre vulnérabilité dans la base CVE