VDB
Sign up
MEDIUM6.5

GHSA-pj33-75x5-32j4

RabbitMQ HTTP API's queue deletion endpoint does not verify that the user has a required permission

Quick fix

GHSA-pj33-75x5-32j4 — rabbit_common: upgrade to the fixed version with the command below.

mix deps.update rabbit_common

Details

### Summary

Queue deletion via the HTTP API was not verifying the `configure` permission of the user.

### Impact

Users who had all of the following:

1. Valid credentials 2. Some permissions for the target virtual host 3. HTTP API access

could delete queues it had no (deletion) permissions for.

### Workarounds

Disable management plugin and use, for example, [Prometheus and Grafana](https://www.rabbitmq.com/docs/prometheus) for monitoring.

### OWASP Classification

OWASP Top10 A01:2021 – Broken Access Control

Are you affected?

Enter the version of the package you're using.

Affected packages

Hex/rabbit_common
Introduced in: 3.12.7Fixed in: 3.12.11
Fixmix deps.update rabbit_common

References