Description
RabbitMQ before 3.4.0 allows remote attackers to bypass the loopback_users restriction via a crafted X-Forwareded-For header.
References
http://www.rabbitmq.com/release-notes/README-3.4.0.txt
Vendor Advisory
http://www.rabbitmq.com/release-notes/README-3.4.0.txt
Vendor Advisory
CVSS impact metrics
AV:N/AC:L/Au:N/C:N/I:P/A:N
5 · Medium
Information
Source identifier
Vulnerability status
Modified
Published
2015-01-20T15:59:08.233Z
11 years agoLast modified
2026-06-17T00:18:28.480Z
2 months ago