RabbitMQ의 취약점이 OAuth 비밀키를 유출할 수 있다는 보안 연구 결과.
RabbitMQ 메시지 브로커 서비스에서 발견된 두 가지 접근 제어 관련 취약점이 공격자에게 OAuth 클라이언트 비밀키를 유출하고, 기업 메시징 인프라를 인수 위험에 노출할 수 있다는 연구 결과가 발표되었습니다. 이 취약점은 테넌트 경계를 우회할 수 있는 가능성도 포함되어 있습니다. 보안을 강화하기 위한 신속한 조치가 필요합니다.
RabbitMQ vulnerabilities could leak OAuth secrets according to security researchers.
Details have emerged about two access control-related vulnerabilities in the RabbitMQ message broker service that could allow attackers to leak OAuth client secrets and expose enterprise messaging infrastructure to takeover risks. The flaws identified also enable potential bypassing of tenant boundaries. Prompt action is required to enhance security measures.