The metrics-collection component in RabbitMQ for Pivotal Cloud Foundry (PCF) 1.6.x before 1.6.4 logs command lines of failed commands, which might allow context-dependent attackers to obtain sensitive information by reading the log data, as demonstrated by a syslog message that contains credentials from a command line.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:a:pivotal_software:rabbitmq:1.6.1:*:*:*:*:*:*:*",
"cpe:2.3:a:pivotal_software:rabbitmq:1.6.2:*:*:*:*:*:*:*",
"cpe:2.3:a:pivotal_software:rabbitmq:1.6.3:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "1.6.1"
},
{
"last_affected": "1.6.1"
},
{
"introduced": "1.6.2"
},
{
"last_affected": "1.6.2"
},
{
"introduced": "1.6.3"
},
{
"last_affected": "1.6.3"
}
],
"source": "CPE_STRING",
"vendor_product": "pivotal_software:rabbitmq"
}
]
}