It was discovered that RabbitMQ incorrectly handled MQTT (MQ Telemetry Transport) authentication. A remote attacker could use this issue to authenticate successfully with an existing username by omitting the password.
{ "availability": "No subscription required", "binaries": [ { "binary_version": "3.2.4-1ubuntu0.1", "binary_name": "rabbitmq-server" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_version": "3.5.7-1ubuntu0.16.04.2", "binary_name": "rabbitmq-server" } ] }