Command Line Credential Exposure in RabbitMQ C AMQP Client Library by Alanxz
CVE-2023-35789
5.5MEDIUM
What is CVE-2023-35789?
A security vulnerability has been identified in the RabbitMQ C AMQP client library that affects version 0.13.0. This issue arises from the method of entering credentials solely through the command line for operations such as amqp-publish or amqp-consume. As a result, these credentials are exposed to local attackers, as they can list running processes and view the command and its arguments. It is essential for users of the RabbitMQ C AMQP client library to be aware of this vulnerability and take appropriate measures to mitigate risks associated with credential exposure.
