CVE-2023-35789 affects the rabbitmq-c AMQP client library up to version 0.13.0, where credentials provided via command-line arguments are exposed to local attackers. This vulnerability has a CVSS score of 5.5 (Medium), indicating a low attack complexity and requiring local access, with a high potential for confidentiality impact due to credential disclosure. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.13.0CPE matchmatch criteria | cpe:2.3:a:rabbitmq-c_project:rabbitmq-c:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
rabbitmq-c vulnerabilities
Jun 16, 2026rabbitmq-c/librabbitmq: Insecure credentials submission
Jun 16, 2023An issue was discovered in the C AMQP client library (aka rabbitmq-c) through 0.13.0 for RabbitMQ. Credentials can only be entered on the command line (e.g., for amqp-publish or amqp-consume) and are thus visible to local attackers by listing a process and its arguments.
Jun 13, 2023