Security Advisory
CVE-2014-9494
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
RabbitMQ before 3.4.0 allows remote attackers to bypass the loopback_users restriction via a crafted X-Forwareded-For header.