Total vulnerabilities in the database
The metrics-collection component in RabbitMQ for Pivotal Cloud Foundry (PCF) 1.6.x before 1.6.4 logs command lines of failed commands, which might allow context-dependent attackers to obtain sensitive information by reading the log data, as demonstrated by a syslog message that contains credentials from a command line.
Software | From | Fixed in |
---|---|---|
pivotal_software / rabbitmq | 1.6.2 | 1.6.2.x |
pivotal_software / rabbitmq | 1.6.1 | 1.6.1.x |
pivotal_software / rabbitmq | 1.6.3 | 1.6.3.x |
pivotal_software / rabbitmq | 1.6.0 | 1.6.0.x |