CVE-2022-31008 is a high-severity vulnerability affecting RabbitMQ versions prior to 3.10.2, 3.9.18, and 3.8.32, specifically impacting the shovel and federation plugins. The vulnerability stems from the use of a predictable secret to encrypt sensitive URI data, which could lead to its deobfuscation and exposure in node logs under specific exception conditions. With a CVSS score of 7.5, this network-exploitable flaw could result in high confidentiality impact without requiring user interaction or complex attack methods. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.9.0, < 3.9.18CPE matchmatch criteria | cpe:2.3:a:broadcom:rabbitmq_server:*:*:*:*:*:*:*:* | ||
>= 3.10.0, < 3.10.2CPE matchmatch criteria | cpe:2.3:a:broadcom:rabbitmq_server:*:*:*:*:*:*:*:* | ||
< 3.8.32CPE matchmatch criteria | cpe:2.3:a:vmware:rabbitmq:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.