Bug 2541491 (CVE-2026-67236)
| Summary: | CVE-2026-67236 rabbitmq-server: rabbitmq-server: Information disclosure via insecure authentication cookies | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | eglynn, jjoyce, jpretori, jschluet, lhh, mburns, mgarciac |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in rabbitmq-server. This vulnerability allows information disclosure due to insecure handling of authentication cookies following a login request. The application stores base64-encoded user credentials in a cookie that lacks essential security flags, such as Secure, HttpOnly, and SameSite. An attacker able to intercept unencrypted traffic, execute scripts in the victim's session, or access local browser storage can retrieve the cookie and decode plaintext login credentials.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-09-25 16:12:15 UTC
|