CVE-2016-9877
published 2016-12-29CVE-2016-9877: An issue was discovered in Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before 3.6.6 and RabbitMQ for PCF 1.5.x before 1.5.20, 1.6.x before 1.6.12, and 1.7.x…
PriorityP349critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
1.38%
69.0th percentile
An issue was discovered in Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before 3.6.6 and RabbitMQ for PCF 1.5.x before 1.5.20, 1.6.x before 1.6.12, and 1.7.x before 1.7.7. MQTT (MQ Telemetry Transport) connection authentication with a username/password pair succeeds if an existing username is provided but the password is omitted from the connection request. Connections that use TLS with a client-provided certificate are not affected.
Affected
81 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| broadcom | rabbitmq_server | — | — |
| broadcom | rabbitmq_server | — | — |
| broadcom | rabbitmq_server | — | — |
| broadcom | rabbitmq_server | — | — |
| broadcom | rabbitmq_server | — | — |
| broadcom | rabbitmq_server | — | — |
| broadcom | rabbitmq_server | — | — |
| broadcom | rabbitmq_server | — | — |
| broadcom | rabbitmq_server | — | — |
| broadcom | rabbitmq_server | — | — |
| broadcom | rabbitmq_server | — | — |
| broadcom | rabbitmq_server | — | — |
| broadcom | rabbitmq_server | — | — |
| broadcom | rabbitmq_server | — | — |
| broadcom | rabbitmq_server | — | — |
| broadcom | rabbitmq_server | — | — |
| broadcom | rabbitmq_server | — | — |
| broadcom | rabbitmq_server | — | — |
| broadcom | rabbitmq_server | — | — |
| broadcom | rabbitmq_server | — | — |
| broadcom | rabbitmq_server | — | — |
| broadcom | rabbitmq_server | — | — |
| broadcom | rabbitmq_server | — | — |
| broadcom | rabbitmq_server | — | — |
| broadcom | rabbitmq_server | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
RabbitMQ vulnerability
vendor_ubuntu·2017-07-31
CVE-2016-9877 RabbitMQ vulnerability
Title: RabbitMQ vulnerability
Summary: RabbitMQ could allow unintended access to network services.
It was discovered that RabbitMQ incorrectly handled MQTT (MQ Telemetry
Transport) authentication. A remote attacker could use this issue to
authenticate successfully with an existing username by omitting the
password.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
rabbitmq: MQTT connection authentication succeeds with empty password
vendor_redhat·2016-12-20·CVSS 9.8
CVE-2016-9877 [CRITICAL] CWE-287 rabbitmq: MQTT connection authentication succeeds with empty password
rabbitmq: MQTT connection authentication succeeds with empty password
An issue was discovered in Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before 3.6.6 and RabbitMQ for PCF 1.5.x before 1.5.20, 1.6.x before 1.6.12, and 1.7.x before 1.7.7. MQTT (MQ Telemetry Transport) connection authentication with a username/password pair succeeds if an existing username is provided but the password is omitted from the connection request. Connections that use TLS with a client-provided certificate are not affected.
Package: rabbitmq-server (Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6) - Will not fix
Package: rabbitmq-server (Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7) - Will not fix
Package: rabbitmq-server (Red Hat Enterprise Linux OpenStack Plat
Debian
CVE-2016-9877: rabbitmq-server - An issue was discovered in Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before 3....
vendor_debian·2016·CVSS 9.8
CVE-2016-9877 [CRITICAL] CVE-2016-9877: rabbitmq-server - An issue was discovered in Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before 3....
An issue was discovered in Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before 3.6.6 and RabbitMQ for PCF 1.5.x before 1.5.20, 1.6.x before 1.6.12, and 1.7.x before 1.7.7. MQTT (MQ Telemetry Transport) connection authentication with a username/password pair succeeds if an existing username is provided but the password is omitted from the connection request. Connections that use TLS with a client-provided certificate are not affected.
Scope: local
bookworm: resolved (fixed in 3.6.6-1)
bullseye: resolved (fixed in 3.6.6-1)
forky: resolved (fixed in 3.6.6-1)
sid: resolved (fixed in 3.6.6-1)
trixie: resolved (fixed in 3.6.6-1)
GHSA
GHSA-fjmp-8qvg-p73x: An issue was discovered in Pivotal RabbitMQ 3
ghsa_unreviewed·2022-05-13
CVE-2016-9877 [CRITICAL] CWE-284 GHSA-fjmp-8qvg-p73x: An issue was discovered in Pivotal RabbitMQ 3
An issue was discovered in Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before 3.6.6 and RabbitMQ for PCF 1.5.x before 1.5.20, 1.6.x before 1.6.12, and 1.7.x before 1.7.7. MQTT (MQ Telemetry Transport) connection authentication with a username/password pair succeeds if an existing username is provided but the password is omitted from the connection request. Connections that use TLS with a client-provided certificate are not affected.
OSV
CVE-2016-9877: An issue was discovered in Pivotal RabbitMQ 3
osv·2016-12-29·CVSS 9.8
CVE-2016-9877 [CRITICAL] CVE-2016-9877: An issue was discovered in Pivotal RabbitMQ 3
An issue was discovered in Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before 3.6.6 and RabbitMQ for PCF 1.5.x before 1.5.20, 1.6.x before 1.6.12, and 1.7.x before 1.7.7. MQTT (MQ Telemetry Transport) connection authentication with a username/password pair succeeds if an existing username is provided but the password is omitted from the connection request. Connections that use TLS with a client-provided certificate are not affected.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9877 rabbitmq-server: rabbitmq: MQTT connection authentication succeeds with empty password [fedora-all]
bugzilla·2017-01-03·CVSS 9.8
CVE-2016-9877 [CRITICAL] CVE-2016-9877 rabbitmq-server: rabbitmq: MQTT connection authentication succeeds with empty password [fedora-all]
CVE-2016-9877 rabbitmq-server: rabbitmq: MQTT connection authentication succeeds with empty password [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2016-9877 rabbitmq: MQTT connection authentication succeeds with empty password
bugzilla·2017-01-03·CVSS 9.8
CVE-2016-9877 [CRITICAL] CVE-2016-9877 rabbitmq: MQTT connection authentication succeeds with empty password
CVE-2016-9877 rabbitmq: MQTT connection authentication succeeds with empty password
It was found that RabbitMQ's MQTT (MQ Telemetry Transport) connection authentication with a username/password pair succeeds if an existing username is provided but the password is omitted from the connection request. Connections that use TLS with a client-provided certificate are not affected.
Discussion:
External References:
https://pivotal.io/security/cve-2016-9877
---
Created rabbitmq-server tracking bugs for this issue:
Affects: epel-all [bug 1409749]
Affects: fedora-all [bug 1409750]
---
Upstream Fix:
https://github.com/rabbitmq/rabbitmq-mqtt/issues/96, This seems to be upstream fix
https://github.com/rabbitmq/rabbitmq-mqtt/commit/157948d86d391a325ac9702f78976c175ced58be
https://github.com/r
Bugzilla
CVE-2016-9877 rabbitmq-server: rabbitmq: MQTT connection authentication succeeds with empty password [epel-all]
bugzilla·2017-01-03·CVSS 9.8
CVE-2016-9877 [CRITICAL] CVE-2016-9877 rabbitmq-server: rabbitmq: MQTT connection authentication succeeds with empty password [epel-all]
CVE-2016-9877 rabbitmq-server: rabbitmq: MQTT connection authentication succeeds with empty password [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue aff
http://www.debian.org/security/2017/dsa-3761http://www.securityfocus.com/bid/95065https://pivotal.io/security/cve-2016-9877https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03880en_ushttp://www.debian.org/security/2017/dsa-3761http://www.securityfocus.com/bid/95065https://pivotal.io/security/cve-2016-9877https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03880en_us
2016-12-29
Published