Impact
The amqp091-go client retains the plain text password in exported fields of the PlainAuth struct after a successful PLAIN authentication handshake. This means that any code with access to the Connection.Config.SASL object—such as reflective loggers, monitoring agents, debugging utilities, or panic handlers—can read and potentially log the credentials. The flaw is a classic example of insecure storage of sensitive data, classified as CWE-316, and allows an attacker with code execution or log access to capture valid RabbitMQ credentials, potentially leading to unauthorized broker access or lateral movement.
Affected Systems
All deployments using rabbitmq:amqp091-go older than version 1.13.0 are affected. The issue is present in any build that has not been updated to the patched release.
Risk and Exploitability
The CVSS score of 7 indicates high severity, but the EPSS score of less than 1% suggests a low probability of exploitation in the wild. Because the vulnerability requires access to the application’s process or its logs, the attack vector is likely local or requires a compromised application. The vulnerability is not listed in the CISA KEV catalog, implying no confirmed widespread exploits yet.
OpenCVE Enrichment
Github GHSA