CVE-2026-59271
5.3
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Summary
When the RabbitMQ management aliveness check fails, the configured admin password is embedded in cleartext in the thrown exception message. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Spring | Spring AMQP | 4.1.0 | affected |
| Spring | Spring AMQP | 4.0.0 <= 4.0.4 | affected |
| Spring | Spring AMQP | 3.2.0 <= 3.2.12 | affected |
| Spring | Spring AMQP | 0 <= 2.4.18 | affected |
Weaknesses
- CWE-209 Generation of Error Message Containing Sensitive Information
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.