RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, RabbitMQ AMQP 0-9-1 allows an existing consumer to keep receiving messages after OAuth token expiry or connection.update_secret refresh to reduced scopes because existing consumers are not canceled or reauthorized at delivery time after the channel user state changes. This issue is fixed in version 4.2.6.
3.6.10-13.6.10-1ubuntu0.13.6.10-1ubuntu0.33.6.10-1ubuntu0.43.6.10-1ubuntu0.53.7.18-13.7.8-4ubuntu23.8.2-0ubuntu13.8.2-0ubuntu1.13.8.2-0ubuntu1.23.8.2-0ubuntu1.33.8.2-0ubuntu1.43.8.2-0ubuntu1.53.8.3-0ubuntu0.13.8.3-0ubuntu0.2+1 more3.5.4-13.5.4-33.5.4-3.13.5.7-13.5.7-1ubuntu0.16.04.13.5.7-1ubuntu0.16.04.23.5.7-1ubuntu0.16.04.43.5.7-1ubuntu0.16.04.4+esm13.5.7-1ubuntu0.16.04.4+esm2Exploitability
AV:NAC:LAT:PPR:LUI:NVulnerable System
VC:NVI:NVA:NSubsequent System
SC:HSI:NSA:NCVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N