Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS1oM2doLTk3OHItNzQ3d84AATUz

puppetlabs-rabbitmq allows local users to obtain sensitive information

puppetlabs-rabbitmq 3.0 through 4.1 stores the RabbitMQ Erlang cookie value in the facts of a node, which allows local users to obtain sensitive information as demonstrated by using Facter.

Permalink: https://github.com/advisories/GHSA-h3gh-978r-747w
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oM2doLTk3OHItNzQ3d84AATUz
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Low
Classification: General
Published: almost 2 years ago
Updated: about 1 year ago


Identifiers: GHSA-h3gh-978r-747w, CVE-2014-9568
References: Blast Radius: 1.0

Affected Packages

hex:puppetlabs-rabbitmq
Affected Version Ranges: >= 3.0, <= 4.1
Fixed in: 5.0