UbuntuUpdates.org

Package "rabbitmq-server"

Name: rabbitmq-server

Description:

AMQP server written in Erlang

Latest version: 4.0.5-2ubuntu2.1
Release: plucky (25.04)
Level: security
Repository: main
Homepage: https://www.rabbitmq.com/

Links


Download "rabbitmq-server"


Other versions of "rabbitmq-server" in Plucky

Repository Area Version
base main 4.0.5-2ubuntu2
updates main 4.0.5-2ubuntu2.1

Changelog

Version: 4.0.5-2ubuntu2.1 2025-09-23 22:06:58 UTC

  rabbitmq-server (4.0.5-2ubuntu2.1) plucky-security; urgency=medium

  * SECURITY UPDATE: authorization headers logged in plaintext (in base64)
    - debian/patches/CVE-2025-50200.patch: fix the exception logged by
      Cowboy caused by double reply in src/rabbit_mgmt_util.erl,
      src/rabbit_mgmt_wm_exchange_publish.erl,
      src/rabbit_mgmt_wm_queue_actions.erl,
      src/rabbit_mgmt_wm_queue_get.erl.
    - CVE-2025-50200

 -- Marc Deslauriers <email address hidden> Fri, 19 Sep 2025 11:39:21 -0400

CVE-2025-50200 RabbitMQ is a messaging and streaming broker. In versions 3.13.7 and prior, RabbitMQ is logging authorization headers in plaintext encoded in base64.



About   -   Send Feedback to @ubuntu_updates