{"id":"USN-7763-1","summary":"rabbitmq-server vulnerability","details":"It was discovered that RabbitMQ Server incorrectly included authorization\nheaders when logging. A local attacker could possibly use this issue to\nobtain sensitive information.","modified":"2025-10-13T04:42:23Z","published":"2025-09-23T17:14:09.650242Z","related":["UBUNTU-CVE-2025-50200"],"upstream":["CVE-2025-50200","UBUNTU-CVE-2025-50200"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-7763-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-50200"}],"affected":[{"package":{"name":"rabbitmq-server","ecosystem":"Ubuntu:25.04","purl":"pkg:deb/ubuntu/rabbitmq-server@4.0.5-2ubuntu2.1?arch=source&distro=plucky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.0.5-2ubuntu2.1"}]}],"versions":["3.12.1-1ubuntu2","4.0.5-2ubuntu1","4.0.5-2ubuntu2"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"rabbitmq-server","binary_version":"4.0.5-2ubuntu2.1"}]},"database_specific":{"cves_map":{"cves":[{"severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"},{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2025-50200"}],"ecosystem":"Ubuntu:25.04"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7763-1.json"}}],"schema_version":"1.7.3"}