{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aibmfinancial_transaction_manager_for_multiplatformswift_services/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ibm:financial_transaction_manager_for_multiplatform:*:*:*:*:*:swift_services:*:*"],"_cs_cves":[{"cvss":6.4,"id":"CVE-2024-49339"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["RabbitMQ"],"_cs_severities":["low"],"_cs_tags":["vulnerability","information-disclosure"],"_cs_type":"advisory","_cs_vendors":["Broadcom"],"content_html":"\u003cp\u003eA security vulnerability has been identified in RabbitMQ which allows a remote, authenticated attacker to gain unauthorized access to sensitive information. The flaw relates to CVE-2024-49339. Successful exploitation of this vulnerability could allow an attacker to bypass intended access controls and view data that should be restricted based on their privilege level. Defenders should review their RabbitMQ configurations and ensure all instances are updated to the vendor-provided security patches that address this specific vulnerability. As this requires prior authentication, organizations should also audit existing user permissions and restrict access to the RabbitMQ management interface to trusted internal networks.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the unauthorized disclosure of information held within the RabbitMQ environment. This impacts organizations relying on RabbitMQ for secure message queuing and data distribution, potentially exposing sensitive business logic or data payloads to authenticated users who should not have access.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch RabbitMQ to the latest version as recommended by the vendor to address CVE-2024-49339.\u003c/li\u003e\n\u003cli\u003eAudit RabbitMQ user permissions to ensure the principle of least privilege is applied, mitigating the impact of an authenticated attacker.\u003c/li\u003e\n\u003cli\u003eRestrict access to the RabbitMQ management API to authorized administrative subnets.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-24T14:01:05Z","date_published":"2026-09-24T14:01:05Z","id":"https://feed.craftedsignal.io/briefs/2026-09-rabbitmq-info-disclosure/","summary":"An authenticated, remote attacker can exploit a vulnerability in RabbitMQ to perform unauthorized disclosure of sensitive information.","title":"Information Disclosure Vulnerability in RabbitMQ","url":"https://feed.craftedsignal.io/briefs/2026-09-rabbitmq-info-disclosure/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:ibm:financial_transaction_manager_for_multiplatform:*:*:*:*:*:swift_services:*:*","version":"https://jsonfeed.org/version/1.1"}