CVE-2015-8786
published 2016-12-09CVE-2015-8786: The Management plugin in RabbitMQ before 3.6.1 allows remote authenticated users with certain privileges to cause a denial of service (resource consumption)…
PriorityP429medium6.5CVSS 3.0
AVNACLPRLUINSUCNINAH
EPSS
3.50%
87.9th percentile
The Management plugin in RabbitMQ before 3.6.1 allows remote authenticated users with certain privileges to cause a denial of service (resource consumption) via the (1) lengths_age or (2) lengths_incr parameter.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rabbitmq-server | < rabbitmq-server 3.6.5-1 (bookworm) | rabbitmq-server 3.6.5-1 (bookworm) |
| oracle | solaris | — | — |
| pivotal_software | rabbitmq | — | — |
| rabbitmq | rabbitmq-server | >= 0 < 3.6.5-1 | 3.6.5-1 |
| rabbitmq | rabbitmq-server | >= 0 < 3.6.5-1 | 3.6.5-1 |
| rabbitmq | rabbitmq-server | >= 0 < 3.6.5-1 | 3.6.5-1 |
| rabbitmq | rabbitmq-server | >= 0 < 3.6.5-1 | 3.6.5-1 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.06.8MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:C
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
rabbitmq-server: DoS via lengths_age or lengths_incr parameter in the management plugin
vendor_redhat·2015-12-29·CVSS 6.5
CVE-2015-8786 [MEDIUM] CWE-400 rabbitmq-server: DoS via lengths_age or lengths_incr parameter in the management plugin
rabbitmq-server: DoS via lengths_age or lengths_incr parameter in the management plugin
The Management plugin in RabbitMQ before 3.6.1 allows remote authenticated users with certain privileges to cause a denial of service (resource consumption) via the (1) lengths_age or (2) lengths_incr parameter.
A resource-consumption flaw was found in RabbitMQ Server, where the lengths_age or lengths_incr parameters were not validated in the management plugin. Remote, authenticated users with certain privileges could exploit this flaw to cause a denial of service by passing values which were too large.
Package: rabbitmq-server (Red Hat OpenStack Platform 10 (Newton)) - Not affected
Package: rabbitmq-server (Red Hat OpenStack Platform 11 (Ocata)) - Not affected
Package: rabbitmq-server (Red Hat Ope
Debian
CVE-2015-8786: rabbitmq-server - The Management plugin in RabbitMQ before 3.6.1 allows remote authenticated users...
vendor_debian·2015·CVSS 6.5
CVE-2015-8786 [MEDIUM] CVE-2015-8786: rabbitmq-server - The Management plugin in RabbitMQ before 3.6.1 allows remote authenticated users...
The Management plugin in RabbitMQ before 3.6.1 allows remote authenticated users with certain privileges to cause a denial of service (resource consumption) via the (1) lengths_age or (2) lengths_incr parameter.
Scope: local
bookworm: resolved (fixed in 3.6.5-1)
bullseye: resolved (fixed in 3.6.5-1)
forky: resolved (fixed in 3.6.5-1)
sid: resolved (fixed in 3.6.5-1)
trixie: resolved (fixed in 3.6.5-1)
GHSA
GHSA-c22c-f732-2pwg: The Management plugin in RabbitMQ before 3
ghsa_unreviewed·2022-05-14
CVE-2015-8786 [MEDIUM] GHSA-c22c-f732-2pwg: The Management plugin in RabbitMQ before 3
The Management plugin in RabbitMQ before 3.6.1 allows remote authenticated users with certain privileges to cause a denial of service (resource consumption) via the (1) lengths_age or (2) lengths_incr parameter.
OSV
CVE-2015-8786: The Management plugin in RabbitMQ before 3
osv·2016-12-09·CVSS 6.5
CVE-2015-8786 [MEDIUM] CVE-2015-8786: The Management plugin in RabbitMQ before 3
The Management plugin in RabbitMQ before 3.6.1 allows remote authenticated users with certain privileges to cause a denial of service (resource consumption) via the (1) lengths_age or (2) lengths_incr parameter.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-8786 rabbitmq-server: DoS via lengths_age or lengths_incr parameter in the management plugin
bugzilla·2016-12-13·CVSS 6.5
CVE-2015-8786 [MEDIUM] CVE-2015-8786 rabbitmq-server: DoS via lengths_age or lengths_incr parameter in the management plugin
CVE-2015-8786 rabbitmq-server: DoS via lengths_age or lengths_incr parameter in the management plugin
The Management plugin in RabbitMQ before 3.6.1 allows remote
authenticated users with certain privileges to cause a denial of
service (resource consumption) via the (1) lengths_age or (2)
lengths_incr parameter.
Upstream bug:
https://github.com/rabbitmq/rabbitmq-management/issues/97
Upstream patches:
https://github.com/rabbitmq/rabbitmq-management/pull/106/commits/5ebc159d3f65ab230e3f261e81ee49d00ebc57c3
https://github.com/rabbitmq/rabbitmq-management/pull/106/commits/298d86fe8cb6865bf50cf91f274b1872cb7bd7ba
Discussion:
Created rabbitmq-server tracking bugs for this issue:
Affects: epel-all [bug 1404151]
---
This issue has been addressed in the following products:
Red Hat OpenSt
Bugzilla
CVE-2015-8786 rabbitmq-server: DoS via lengths_age or lengths_incr parameter in the management plugin [epel-all]
bugzilla·2016-12-13·CVSS 6.5
CVE-2015-8786 [MEDIUM] CVE-2015-8786 rabbitmq-server: DoS via lengths_age or lengths_incr parameter in the management plugin [epel-all]
CVE-2015-8786 rabbitmq-server: DoS via lengths_age or lengths_incr parameter in the management plugin [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
http://rhn.redhat.com/errata/RHSA-2017-0226.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0530.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0531.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0532.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0533.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/91508https://github.com/rabbitmq/rabbitmq-management/issues/97https://github.com/rabbitmq/rabbitmq-server/releases/tag/rabbitmq_v3_6_1http://rhn.redhat.com/errata/RHSA-2017-0226.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0530.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0531.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0532.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0533.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/91508https://github.com/rabbitmq/rabbitmq-management/issues/97https://github.com/rabbitmq/rabbitmq-server/releases/tag/rabbitmq_v3_6_1
2016-12-09
Published