MEDIUM6.5
GHSA-pj33-75x5-32j4
RabbitMQ HTTP API's queue deletion endpoint does not verify that the user has a required permission
Quick fix
GHSA-pj33-75x5-32j4 — rabbit_common: upgrade to the fixed version with the command below.
mix deps.update rabbit_commonDetails
### Summary
Queue deletion via the HTTP API was not verifying the `configure` permission of the user.
### Impact
Users who had all of the following:
1. Valid credentials 2. Some permissions for the target virtual host 3. HTTP API access
could delete queues it had no (deletion) permissions for.
### Workarounds
Disable management plugin and use, for example, [Prometheus and Grafana](https://www.rabbitmq.com/docs/prometheus) for monitoring.
### OWASP Classification
OWASP Top10 A01:2021 – Broken Access Control
Are you affected?
Enter the version of the package you're using.