Horizon Alert
Summary of the vulnerability and why it matters
This advisory concerns a vulnerability in a Go AMQP client library that could allow a network attacker to weaken transport protection for messages and credentials if older TLS versions are negotiated. The issue is related to the library's TLS configuration not explicitly setting a minimum TLS version, potentially allowing negotiation of obsolete protocols on systems using older Go runtimes.
- Vulnerability may weaken message transport security.
- Confirms exposure and relevance for affected applications.
- Assess client library usage for potential protocol downgrade.
Attack Path
How an attacker could exploit the issue
An attacker on the network could potentially intercept and weaken the transport security for messages and credentials by forcing a connection to use an older, less secure TLS version. This is possible if the RabbitMQ Go client is built with a default Go runtime that permits TLS 1.0 or 1.1 and is configured to connect using an `amqps` URI.
- Network access required to influence TLS.
- Vulnerability triggered by connecting via `amqps` URI.
- Risk of weakened transport security.
Live Threat
Current exploitation, exposure, and threat context
When supported by the advisory, a network attacker could weaken transport protection for AMQP messages and credentials by exploiting a TLS configuration weakness in older builds of the Go AMQP 0.9.1 client. This occurs when the client negotiates an obsolete protocol version, potentially exposing sensitive information exchanged over the connection.
- AMQP messages and credentials.
- Negotiating obsolete TLS protocol versions.
- Weakened transport protection for sensitive data.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability impacts applications using the amqp091-go client library, specifically in how it handles TLS configurations. Application development teams are likely responsible for integrating this library. The first step is to identify all applications utilizing this client, assess their exposure, and confirm which deployments are critical or reachable by network attackers.
- Application development teams own the fix.
- Verify amqp091-go client usage and TLS settings.
- Plan updates during maintenance windows.