Does RabbitMQ use Erlang/OTP SSH library? Is it affected by CVE-2025-32433? #13784
-
Community Support Policy
RabbitMQ version used4.0.5 Erlang version used27.2.x Operating system (distribution) usedLinux How is RabbitMQ deployed?RPM package rabbitmq-diagnostics status outputCluster status of node rabbit@manojclog--0 ... Cluster name: [email protected] Disk Nodes rabbit@manojclog--0 Running Nodes rabbit@manojclog--0 Versions rabbit@manojclog--0: RabbitMQ 4.0.3 on Erlang 26.2.5.5 CPU Cores Node: rabbit@manojclog--0, available CPU cores: 12 Maintenance status Node: rabbit@manojclog--0, status: not under maintenance Alarms (none) Network Partitions (none) Listeners Node: rabbit@manojclog--0, interface: [::], port: 15672, protocol: http, purpose: HTTP API Feature flags Flag: classic_mirrored_queue_version, state: enabled Logs from node 1 (with sensitive values edited out)Cluster status of node rabbit@manojclog--0 ... Cluster name: [email protected] Disk Nodes rabbit@manojclog--0 Running Nodes rabbit@manojclog--0 Versions rabbit@manojclog--0: RabbitMQ 4.0.3 on Erlang 26.2.5.5 CPU Cores Node: rabbit@manojclog--0, available CPU cores: 12 Maintenance status Node: rabbit@manojclog--0, status: not under maintenance Alarms (none) Network Partitions (none) Listeners Node: rabbit@manojclog--0, interface: [::], port: 15672, protocol: http, purpose: HTTP API Feature flags Flag: classic_mirrored_queue_version, state: enabled Logs from node 2 (if applicable, with sensitive values edited out)See https://www.rabbitmq.com/docs/logging to learn how to collect logs
Logs from node 3 (if applicable, with sensitive values edited out)See https://www.rabbitmq.com/docs/logging to learn how to collect logs
rabbitmq.confdefault Steps to deploy RabbitMQ clusterinstall rpm in rocky8 linux container and deploy docker comtainer Steps to reproduce the behavior in questionnone advanced.configSee https://www.rabbitmq.com/docs/configure#config-location to learn how to find advanced.config file location
Application code# PASTE CODE HERE, BETWEEN BACKTICKS Kubernetes deployment file# Relevant parts of K8S deployment that demonstrate how RabbitMQ is deployed
# PASTE YAML HERE, BETWEEN BACKTICKS What problem are you trying to solve?As per GHSA-37cp-fgq5-7wc2 this vulnerability, is rabbitmq impacted in any way. Does rabbitmq use erlang ssh library? if yes should take the fix given. If not, can we say it is not impacted? |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment
-
Duplicate of #13778 |
Beta Was this translation helpful? Give feedback.
Duplicate of #13778