Severity
7.5HIGH
EPSS
3.1%
top 13.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 23
Latest updateApr 15

Description

Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is vulnerable to a denial of service attack. The "X-Reason" HTTP Header can be leveraged to insert a malicious Erlang format string that will expand and consume the heap, resulting in the server crashing.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages8 packages

CVEListV5pivotal/rabbitmq_for_pivotal_platform1.161.16.7+1
CVEListV5pivotal/rabbitmq3.7v3.7.21+1
NVDpivotal_software/rabbitmq1.16.01.16.7+2
NVDbroadcom/rabbitmq_server3.8.03.8.1
Debianrabbitmq-server< 3.8.3-1+3

Also affects: Debian Linux 9.0, Fedora 30, 31

🔴Vulnerability Details

5
GHSA
Pivotal RabbitMQ is vulnerable to a denial of service attack2022-05-24
OSV
Pivotal RabbitMQ is vulnerable to a denial of service attack2022-05-24
OSV
rabbitmq-server vulnerabilities2021-06-24
OSV
CVE-2019-11287: Pivotal RabbitMQ, versions 32019-11-23
CVEList
RabbitMQ Web Management Plugin DoS via heap overflow2019-11-22

📋Vendor Advisories

4
Oracle
Oracle Oracle Communications Applications Risk Matrix: Core (Pivotal RabbitMQ) — CVE-2019-112872023-04-15
Ubuntu
RabbitMQ vulnerabilities2021-06-24
Red Hat
rabbitmq-server: "X-Reason" HTTP Header can be leveraged to insert a malicious string leading to DoS2019-12-13
Debian
CVE-2019-11287: rabbitmq-server - Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and R...2019

💬Community

3
Bugzilla
CVE-2019-11287 rabbitmq-server: "X-Reason" HTTP Header can be leveraged to insert a malicious string leading to DoS [openstack-rdo]2019-12-13
Bugzilla
CVE-2019-11287 rabbitmq-server: "X-Reason" HTTP Header can be leveraged to insert a malicious string leading to DoS2019-12-13
Bugzilla
CVE-2019-11287 rabbitmq-server: "X-Reason" HTTP Header can be leveraged to insert a malicious string leading to DoS [fedora-all]2019-12-13
CVE-2019-11287 (HIGH CVSS 7.5) | Pivotal RabbitMQ | cvebase.io