If this behavior is configurable or other mitigation can be devised, or if it gets patched upstream in rabbitmq, then a security note (not advisory) may be appropriate to let operators know about the risk and what they can do.
If this behavior is configurable or other mitigation can be devised, or if it gets patched upstream in rabbitmq, then a security note (not advisory) may be appropriate to let operators know about the risk and what they can do.