rabbitmq-default-password: RabbitMQ Default Password

日期: 2025-09-01 | 影响软件: RabbitMQ | POC: 已公开

漏洞描述

app="RabbitMQ-Management"

PoC代码[已公开]

id: rabbitmq-default-password

info:
    name: RabbitMQ Default Password
    author: mumu0215(https://github.com/mumu0215)
    severity: high
    verified: true
    description: app="RabbitMQ-Management"

rules:
    r0:
        request:
            method: GET
            path: /api/whoami
        expression: response.status == 401
    r1:
        request:
            method: GET
            path: /api/whoami
            headers:
                Authorization: Basic Z3Vlc3Q6Z3Vlc3Q=
        expression: response.status == 200 && response.body.bcontains(b"\"name\":\"guest\"")
expression: r0() && r1()

相关漏洞推荐