Snyk has a proof-of-concept or detailed explanation of how to exploit this vulnerability.
The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade com.rabbitmq:amqp-client to version 5.35.0 or higher.
Affected versions of this package are vulnerable to Credential Exposure in ConnectionFactoryConfigurator.load(ConnectionFactory, Map<String,String>, String), which concatenates the raw AMQP URI, username and password included, into three IllegalArgumentException messages. A user with read access to the application's logs or error tracking data can obtain the broker password in plaintext, by reading the startup failure recorded when configuration supplies a URI that java.net.URI rejects. This requires property file or Map based configuration and a URI that fails to parse, such as one whose password contains a space, and the chained URISyntaxException carries the same credential bearing string again, so redacting only the top level message leaves it exposed.