Impact
RabbitMQ versions from 4.0.0 up to 4.3.3, 4.2.9, 4.1.14, and 4.0.23 contain a flaw in the AMQP 1.0 management GET /bindings endpoint, which enumerates all bindings in a virtual host. The endpoint performs no resource‑level permission checks and returns the full list to any authenticated AMQP user, regardless of whether they are a management, monitoring, or administrator. This allows an attacker with a valid AMQP user account to discover every source exchange, destination queue or exchange, routing key, and binding argument present in the virtual host, thereby compromising confidentiality of broker topology.
Affected Systems
The affected vendor is RabbitMQ for their RabbitMQ Server product. Vulnerable releases include 4.0.0 through 4.3.3, 4.2.9, 4.1.14, and 4.0.23.
Risk and Exploitability
The CVSS score of 6.3 indicates a medium severity. No EPSS score is available, so the current exploit probability cannot be quantified precisely. The issue is not listed in the CISA KEV catalog. The likely attack vector is any authenticated AMQP 1.0 client that can open a management link pair; users without elevated tags can still retrieve the full binding topology. An attacker can enumerate the entire routing topology of any virtual host they can connect to, enabling social engineering, targeted attacks, or further exploitation of exposed resources.
OpenCVE Enrichment