RabbitMQ is a messaging and streaming broker. In versions 3.13.7 and prior, RabbitMQ is logging authorization headers in plaintext encoded in base64. When querying RabbitMQ api with HTTP/s with basic authentication it creates logs with all headers in request, including authorization headers which show base64 encoded username:password. This is easy to decode and afterwards could be used to obtain control to the system depending on credentials. This issue has been patched in version 4.0.8.
History

Fri, 20 Jun 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 20 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}

threat_severity

Moderate


Thu, 19 Jun 2025 16:30:00 +0000

Type Values Removed Values Added
Description RabbitMQ is a messaging and streaming broker. In versions 3.13.7 and prior, RabbitMQ is logging authorization headers in plaintext encoded in base64. When querying RabbitMQ api with HTTP/s with basic authentication it creates logs with all headers in request, including authorization headers which show base64 encoded username:password. This is easy to decode and afterwards could be used to obtain control to the system depending on credentials. This issue has been patched in version 4.0.8.
Title RabbitMQ Node can log Basic Auth header from an HTTP request
Weaknesses CWE-532
References
Metrics cvssV4_0

{'score': 6.7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-06-19T16:14:24.919Z

Updated: 2025-06-20T17:43:55.579Z

Reserved: 2025-06-13T19:17:51.728Z

Link: CVE-2025-50200

cve-icon Vulnrichment

Updated: 2025-06-20T17:42:50.698Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-19T17:15:26.123

Modified: 2025-06-23T20:16:59.783

Link: CVE-2025-50200

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-06-19T16:14:24Z

Links: CVE-2025-50200 - Bugzilla