Impact
A vulnerability in RabbitMQ allows a user with a management tag to read quorum‑queue status for queues in any vhost, because the /api/queues/quorum/:vhost/:queue/status endpoint does not verify that the user can access the specified vhost. The exposed information includes leader, members, Raft term, and commit index, revealing cross‑tenant queue names and cluster topology. This flaw is an authorization bypass (CWE-862).
Affected Systems
RabbitMQ Server. Versions before 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0 are affected. The product is rabbitmq-server and the vulnerability exists in the management plugin.
Risk and Exploitability
The CVSS score of 2.3 indicates a low‑severity impact. Because the exploit requires the management plugin to be enabled and the attacker to possess a management tag, the attack vector is limited to users who already have management‑level access. EPSS is not available and the vulnerability is not listed in CISA KEV, suggesting that exploitation in the wild is unlikely but still possible within an organization where such users exist.
OpenCVE Enrichment