RabbitMQ before 3.4.0 allows remote attackers to bypass the loopback_users restriction via a crafted X-Forwareded-For header.
https://groups.google.com/forum/#%21topic/rabbitmq-users/DMkypbSvIyM
https://exchange.xforce.ibmcloud.com/vulnerabilities/99685