Lucene search

K
freebsdFreeBSD7E9CC7FD-6B3E-46C5-AD6D-409D90D41BBF
HistorySep 19, 2019 - 12:00 a.m.

RabbitMQ-C -- auth credentials visible in commandline tool options

2019-09-1900:00:00
vuxml.freebsd.org
3

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

6.8

Confidence

Low

hadmut reports:

This C library includes 2 command-line tools that can take
credentials as command-line options. The credentials are exposed
as plain-text in the process list. This could allow an attacker
with access to the process list to see the credentials.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchrabbitmq-c< 0.14.0UNKNOWN

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

6.8

Confidence

Low