RabbitMQ before 3.4.0 allows remote attackers to bypass the loopback_users restriction via a crafted X-Forwareded-For header.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Rabbitmq | Pivotal_software | * | 3.3.5 (including) |
Rabbitmq-server | Ubuntu | lucid | * |
Rabbitmq-server | Ubuntu | upstream | * |
Rabbitmq-server | Ubuntu | utopic | * |