default account "guest" has administrator privileges
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
rabbitmq-server (Ubuntu) |
Confirmed
|
Undecided
|
Unassigned |
Bug Description
rabbitmq by default creates an account named "guest" with the password "guest". This account has administrative privileges, and up until version 3.3.0, it is also usable over the network. The version in trusty is 3.2.4.
https:/
https:/
This appears to be common knowledge (so my filing this as a private security bug may be overzealous) and indeed is relied upon in many places. I discovered it while working on an internal monitoring script, and here's another example: https:/
Since it would not affect existing installations, it may be reasonable to alter this behaviour, even in a stable release.
description: | updated |
information type: | Private Security → Public Security |
Changed in rabbitmq-server (Ubuntu): | |
status: | New → Confirmed |