Briefing

RabbitMQ Access Control Flaws Could Leak OAuth Secrets and Bypass Tenant Boundaries

security
by [email protected] (The Hacker News) ·

Patch RabbitMQ to the latest version that fixes the OAuth client secret leakage and tenant boundary bypass.

What to do now

Patch RabbitMQ immediately to the latest version that addresses the OAuth client secret leakage and tenant boundary bypass.

Summary

RabbitMQ message broker suffers from two access control flaws that could allow attackers to leak OAuth client secrets and bypass tenant boundaries, exposing enterprise messaging infrastructure to takeover risks.

Miggo's security team identified the first flaw that leaks the broker's confidential OAuth credentials when an attacker crafts a specific request, while the second flaw permits cross‑tenant access to protected queues. Both vulnerabilities are present in the current stable releases of RabbitMQ and can be exploited without authentication. The flaws could enable attackers to compromise the broker, read sensitive data, and potentially hijack the entire messaging system. RabbitMQ maintainers have issued a patch that updates the OAuth handling logic and enforces strict tenant isolation. Users should upgrade to the latest version as soon as possible to mitigate the risk. The incident highlights the importance of rigorous access control in message broker deployments. The patch also includes additional logging to detect suspicious OAuth usage.

Key changes

  • Two access control flaws allow leakage of OAuth client secrets
  • Flaws enable bypass of tenant boundaries in RabbitMQ
  • Both vulnerabilities exist in current stable releases
  • Exploitation requires crafting specific requests, no authentication needed
  • Patch updates OAuth handling logic and enforces tenant isolation
  • Additional logging added to detect suspicious OAuth usage

Affects

enterprise internal

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting