### Impact Shovel and Federation plugins perform URI obfuscation in their worker (link) state. The encryption key used to encrypt the URI was seeded with a predictable secret. This means that in case of certain exceptions related to Shovel and Federation plugins, reasonably easily deobfuscatable data could appear in the node log. Patched versions correctly use a cluster-wide secret for that purpose. ### Patches Patched versions: * `3.10.2` * `3.9.18` * `3.8.32` ### Workarounds Disable Shovel and Federation plugins. ### Credits RabbitMQ core team would like to thank Lajos @luos Gerecs and Anh Nguyen from Erlang Solutions for responsibly disclosing and working with us on a patch for this vulnerability. ### For more information * [Mailing list](https://groups.google.com/forum/#!forum/rabbitmq-users) * [Community Slack](https://rabbitmq-slack.herokuapp.com/)
Update rabbit_common to 3.10.2; rabbit_common to 3.9.18; rabbit_common to 3.8.32 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanRabbitMQ has predictable credential obfuscation seed value used in Shovel and Federation plugins affects rabbit_common (erlang), rabbit_common (erlang), rabbit_common (erlang). Severity is medium. ### Impact Shovel and Federation plugins perform URI obfuscation in their worker (link) state. The encryption key used to encrypt the URI was seeded with a predictable secret. This means that in case of certain exceptions related to Shovel and Federation plugins, reasonably easily deobfuscatable data could appear in the node log. Patched versions correctly use a cluster-wide secret for that purpose. ### Patches Patched versions: * `3.10.2` * `3.9.18` * `3.8.32` ### Workarounds Disable Shovel and Federation plugins. ### Credits RabbitMQ core team would like to thank Lajos @luos Gerecs and Anh Nguyen from Erlang Solutions for responsibly disclosing and working with us on a patch for this vulnerability. ### For more information * [Mailing list](https://groups.google.com/forum/#!forum/rabbitmq-users) * [Community Slack](https://rabbitmq-slack.herokuapp.com/)
AI coding agents often install or upgrade packages automatically in erlang. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
### Impact Shovel and Federation plugins perform URI obfuscation in their worker (link) state. The encryption key used to encrypt the URI was seeded with a predictable secret. This means that in case of certain exceptions related to Shovel and Federation plugins, reasonably easily deobfuscatable data could appear in the node log. Patched versions correctly use a cluster-wide secret for that purpose. ### Patches Patched versions: * `3.10.2` * `3.9.18` * `3.8.32` ### Workarounds Disable Shovel and Federation plugins. ### Credits RabbitMQ core team would like to thank Lajos @luos Gerecs and Anh Nguyen from Erlang Solutions for responsibly disclosing and working with us on a patch for this vulnerability. ### For more information * [Mailing list](https://groups.google.com/forum/#!forum/rabbitmq-users) * [Community Slack](https://rabbitmq-slack.herokuapp.com/)
Update rabbit_common to 3.10.2; rabbit_common to 3.9.18; rabbit_common to 3.8.32 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanRabbitMQ has predictable credential obfuscation seed value used in Shovel and Federation plugins affects rabbit_common (erlang), rabbit_common (erlang), rabbit_common (erlang). Severity is medium. ### Impact Shovel and Federation plugins perform URI obfuscation in their worker (link) state. The encryption key used to encrypt the URI was seeded with a predictable secret. This means that in case of certain exceptions related to Shovel and Federation plugins, reasonably easily deobfuscatable data could appear in the node log. Patched versions correctly use a cluster-wide secret for that purpose. ### Patches Patched versions: * `3.10.2` * `3.9.18` * `3.8.32` ### Workarounds Disable Shovel and Federation plugins. ### Credits RabbitMQ core team would like to thank Lajos @luos Gerecs and Anh Nguyen from Erlang Solutions for responsibly disclosing and working with us on a patch for this vulnerability. ### For more information * [Mailing list](https://groups.google.com/forum/#!forum/rabbitmq-users) * [Community Slack](https://rabbitmq-slack.herokuapp.com/)
AI coding agents often install or upgrade packages automatically in erlang. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|
| rabbit_commonerlang | >=3.10.0,<3.10.2 | 3.10.2 |
|---|---|---|
| rabbit_commonerlang | >=3.9.0,<3.9.18 | 3.9.18 |
| rabbit_commonerlang | >=3.8.0,<3.8.32 | 3.8.32 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| Package | Affected range | Fixed version |
|---|
| rabbit_commonerlang | >=3.10.0,<3.10.2 | 3.10.2 |
|---|---|---|
| rabbit_commonerlang | >=3.9.0,<3.9.18 | 3.9.18 |
| rabbit_commonerlang | >=3.8.0,<3.8.32 | 3.8.32 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard