Horizon Alert
Summary of the vulnerability and why it matters
This advisory concerns a security vulnerability in RabbitMQ, a messaging and streaming broker. The issue, found in the trust-store plugin, could allow an attacker to bypass TLS client authentication by using a forged certificate if specific conditions are met. This could potentially enable unauthorized access to systems relying on this authentication method.
- Unauthorized access to messaging systems.
- Understand RabbitMQ's role in your infrastructure.
- Confirm if RabbitMQ is used and assess exposure.
Attack Path
How an attacker could exploit the issue
An attacker who knows the issuer and serial number of a whitelisted certificate can bypass TLS client authentication. This is possible when the RabbitMQ trust-store plugin is enabled and configured to use a specific verification function. An attacker can then connect to the broker using a forged self-signed certificate that matches the known issuer and serial number, potentially leading to unauthorized access.
- Vulnerability requires trust-store plugin enabled.
- Attacker uses forged cert with known issuer/serial.
- Bypasses TLS authentication for unauthorized access.
Live Threat
Current exploitation, exposure, and threat context
When the RabbitMQ trust-store plugin is enabled and configured as the TLS verify function, an attacker who knows the issuer name and serial number of a whitelisted certificate could connect to the broker using a forged self-signed certificate. This bypasses TLS client authentication under specific conditions.
- Server authentication.
- TLS client authentication bypass.
- Unauthorized broker access.
Operational Fix
Recommended remediation, mitigation, and detection steps
Teams responsible for RabbitMQ deployments, likely platform or infrastructure teams, must first identify all instances of the affected trust-store plugin. Confirming network reachability and business criticality will inform prioritization for remediation, which may involve coordination with application owners and potentially vendor engagement if RabbitMQ is managed as a service.
- Platform/Infrastructure teams own this issue.
- Verify plugin usage and network exposure.
- Plan upgrade during maintenance window.