Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process. RabbitMQ is a messaging and streaming broker. Prior to versions 4.0.22, 4.1.11, 4.2.6, and 4.3.0, accept_content/2 at line 56 calls rabbit_stream_manager:create_super_stream/... directly after is_authorized (which only checks the management tag + vhost access via is_authorized_vhost). The stream-protocol equivalent (rabbit_stream_reader.erl create_super_stream handler) calls rabbit_stream_utils:check_super_stream_management_permitted/4 which enforces configure on the exchange and each partition queue. The HTTP handler omits this call entirely. A user with management tag and vhost access , but no configure permission on any resource , can create super-streams (an exchange + N partition stream queues + bindings) via the HTTP API. The native stream-protocol path enforces configure on each resource; the HTTP path does not, creating a privilege escalation from 'can view' to 'can create persistent cluster-wide resources.' Preconditions include rabbitmq_stream_management plugin enabled management tag + vhost access (no resource permissions needed). This issue is fixed in versions 4.0.22, 4.1.11, 4.2.6, and 4.3.0.
This issue is already fixed upstream in RabbitMQ 4.3.6, which is the version currently built for Fedora rawhide (rabbitmq-server-4.3.6-1.fc46) and Fedora 45 (rabbitmq-server-4.3.6-1.fc45). Fedora 44 (currently 4.2.9) and Fedora 43 (currently 4.0.9) still need attention; backports/rebases for the still-supported stable branches are being worked on. Leaving this report open to track that remaining work.
This issue is already addressed in the rabbitmq-server builds currently shipped in all maintained Fedora branches: * Fedora rawhide: rabbitmq-server-4.3.6-1.fc46 * Fedora 45: rabbitmq-server-4.3.6-1.fc45 * Fedora 44: rabbitmq-server-4.2.9-2.fc44 No new build is required for these branches, so closing as CURRENTRELEASE. Fedora 43 (rabbitmq-server-4.0.9) will NOT be updated for this CVE batch: the upstream 4.0.x line ended at 4.0.9 (later 4.0.x fixes are commercial-only, with no public OSS release) and Fedora 43 reaches end of life on 2026-12-09, so a backport to F43 is not worthwhile.