Impact
The RabbitMQ Java client library allows Java and JVM-based applications to connect to RabbitMQ nodes. Prior to version 5.35.0, the ConnectionFactoryConfigurator.load() method embeds the raw AMQP URI in wrapped exceptions when parsing fails. This URI may include a plaintext username and password, so the exception message can leak broker credentials to anyone who can view logs, startup output, or stack traces. The defect is classified as insecure private data exposure (CWE-509) and results in credential disclosure rather than a code‑execution flaw.
Affected Systems
Affected products are the RabbitMQ Java client libraries identified by com.rabbitmq:amqp-client and rabbitmq:rabbitmq-java-client. Any deployment that includes a version older than 5.35.0 was vulnerable. The issue was fixed in version 5.35.0 and later releases.
Risk and Exploitability
The CVSS score of 5.7 indicates moderate severity; the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Attackers are most likely to exploit this weakness when application logs or error output are accessible to unauthorized parties, which may happen in shared hosting environments, CI systems, or when stack traces are copied to unprotected locations. The flaw does not enable remote code execution, but it can compromise account access by revealing sensitive credentials that are otherwise protected.
OpenCVE Enrichment