Impact
A vulnerability in the RabbitMQ amqp091-go client causes TLS configurations created from URI parsing to omit a minimum protocol version constraint, allowing the use of TLS 1.0 or TLS 1.1. In environments where the Go runtime defaults to accept these legacy protocols, an attacker able to influence TLS negotiation could force the client to use an obsolete protocol, thereby weakening the encryption protecting AMQP messages and credentials. The weakness can lead to loss of confidentiality of data in transit, and potentially compromise credentials used for authentication. The flaw is classified under CWE‑326, highlighting improper validation of cryptographic strength.
Affected Systems
RabbitMQ amqp091-go implementations built with Go runtimes that permit TLS 1.0 or TLS 1.1, specifically versions prior to 1.13.0. The issue is fixed in release 1.13.0 and later, which sets the minimum TLS version to 1.2 in the configuration produced by tlsConfigFromURI.
Risk and Exploitability
The CVSS score of 9.4 marks the vulnerability as critical severity, while the EPSS score of fewer than 1% indicates a very low probability of exploitation at the current time. The vulnerability is not present in the CISA KEV catalog. An attacker would need network access to influence TLS negotiation between a client using the affected library and a server, which is likely feasible in many networked deployments. The lack of a minimum TLS version permits downgrade attacks that could expose sensitive AMQP traffic.
OpenCVE Enrichment
Github GHSA