Activity log for bug #1508698

Date Who What changed Old value New value Message
2015-10-21 21:53:55 Paul Collins bug added bug
2015-10-21 21:54:13 Paul Collins bug added subscriber The Canonical Sysadmins
2015-10-21 21:54:28 Paul Collins bug added subscriber Canonical WebOps
2015-10-21 22:32:31 Paul Collins description Up until version 3.3.0, rabbitmq by default creates an account named "guest" with the password "guest". This account is usable over the network, and it also has administrative privileges. The version in trusty is 3.2.4. https://www.rabbitmq.com/access-control.html https://www.rabbitmq.com/blog/2014/04/02/breaking-things-with-rabbitmq-3-3/ This appears to be common knowledge (so my filing this as a private security bug may be overzealous) and indeed is relied upon in many places. I discovered it while working on an internal monitoring script, and here's another example: https://bugs.launchpad.net/openstack-manuals/+bug/1390419 Since it would not affect existing installations, it may be reasonable to alter this behaviour, even in a stable release. rabbitmq by default creates an account named "guest" with the password "guest". This account has administrative privileges, and up until version 3.3.0, it is also usable over the network. The version in trusty is 3.2.4. https://www.rabbitmq.com/access-control.html https://www.rabbitmq.com/blog/2014/04/02/breaking-things-with-rabbitmq-3-3/ This appears to be common knowledge (so my filing this as a private security bug may be overzealous) and indeed is relied upon in many places. I discovered it while working on an internal monitoring script, and here's another example: https://bugs.launchpad.net/openstack-manuals/+bug/1390419 Since it would not affect existing installations, it may be reasonable to alter this behaviour, even in a stable release.
2015-10-29 18:33:25 Marc Deslauriers information type Private Security Public Security
2015-10-29 18:33:29 Marc Deslauriers rabbitmq-server (Ubuntu): status New Confirmed