RabbitMQ before 3.4.0 allows remote attackers to bypass the loopback_users restriction via a crafted X-Forwareded-For header.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Rabbitmq | Pivotal_software | * | 3.3.5 (including) |
| Rabbitmq-server | Ubuntu | lucid | * |
| Rabbitmq-server | Ubuntu | upstream | * |
| Rabbitmq-server | Ubuntu | utopic | * |