RabbitMQ Management Interface: What to Check Before You Expose It
The RabbitMQ management interface is a browser-based dashboard and HTTP API that gives you visibility into your message broker: queue depths, connection counts, user accounts, and node health. It’s configured for local development by default, not production. Exposing it without checking a handful of settings can hand an attacker full control of your broker.
What the RabbitMQ Management Interface Actually Exposes
Anyone who can reach the management port and log in sees everything: all virtual hosts, queues, exchanges, bindings, message rates, and connected clients. They can also purge queues, publish messages, delete exchanges, and add or remove user accounts.
The interface sits on top of an HTTP API served by the RabbitMQ management plugin, which means an attacker doesn’t need a browser. They can script requests against the API directly. Automated credential stuffing or configuration changes are straightforward once they have a working login.
Is the Management Plugin Enabled by Default?
The management plugin, called rabbitmq_management, is not enabled in a standard RabbitMQ installation. You enable it deliberately with:
rabbitmq-plugins enable rabbitmq_management
The moment it’s enabled, RabbitMQ opens port 15672 and starts serving the UI and API.
The exception is Docker. The official image tagged rabbitmq:management ships with the plugin already active. If you ran a container using that tag, the management interface is running. You may not have intended that.
Default Credentials: Change These First
RabbitMQ changed its management plugin port from 55672 to 15672 in version 3.3.0, released April 2014. The intent was to reduce exposure. It didn’t fix the underlying problem. In a 2015 scan of over 16 million IP addresses, documented in a Tufts University computer security project, servers were still found running on the old port 55672, some with default admin credentials still in place. That was nearly 18 months after the …
