Skip to content
Threat Feed
low advisory

Information Disclosure Vulnerability in RabbitMQ

An authenticated, remote attacker can exploit a vulnerability in RabbitMQ to perform unauthorized disclosure of sensitive information.

CVE search metadata

CVE search record: CVE-2024-49339. Severity: medium. CVSS: 6.4. EPSS: 0.22%. KEV: no. Product: RabbitMQ. Brief: Information Disclosure Vulnerability in RabbitMQ. Brief link: https://feed.craftedsignal.io/briefs/2026-09-rabbitmq-info-disclosure/

A security vulnerability has been identified in RabbitMQ which allows a remote, authenticated attacker to gain unauthorized access to sensitive information. The flaw relates to CVE-2024-49339. Successful exploitation of this vulnerability could allow an attacker to bypass intended access controls and view data that should be restricted based on their privilege level. Defenders should review their RabbitMQ configurations and ensure all instances are updated to the vendor-provided security patches that address this specific vulnerability. As this requires prior authentication, organizations should also audit existing user permissions and restrict access to the RabbitMQ management interface to trusted internal networks.

Impact

Successful exploitation results in the unauthorized disclosure of information held within the RabbitMQ environment. This impacts organizations relying on RabbitMQ for secure message queuing and data distribution, potentially exposing sensitive business logic or data payloads to authenticated users who should not have access.

Recommendation

  • Patch RabbitMQ to the latest version as recommended by the vendor to address CVE-2024-49339.
  • Audit RabbitMQ user permissions to ensure the principle of least privilege is applied, mitigating the impact of an authenticated attacker.
  • Restrict access to the RabbitMQ management API to authorized administrative subnets.

Mitigations

Upgrade RabbitMQ to the latest patched version provided by Broadcom

medium_term IT Operations

CVE-2024-49339