AMQP clear text Authentication Vulnerability in stackstrom #5374
Unanswered
SowmyaSekaran1510
asked this question in
Operations
Replies: 1 comment
-
The default installation for RabbitMQ is clear text. It is up to the site administrator to correctly configure Authentication/Encryption for their environment, you can consult the StackStorm specific information here https://docs.stackstorm.com/install/config/config.html#configure-rabbitmq, and RabbitMQ documentation in general https://www.rabbitmq.com/access-control.html and https://www.rabbitmq.com/ssl.html. If you are reporting a security vulnerability in the StackStorm software, please read and follow the procedure describe here https://docs.stackstorm.com/security.html to report the security concern. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
We are using stactstrom version st2 3.4.1, on Python 3.6.8 in rhel 7 and we are getting this AMQP clear text Authentication Vulnerability from security team. Could you please help us to resolve this Vulnerability??
Beta Was this translation helpful? Give feedback.
All reactions