CVE-2020-5419

CWE-4274 documents4 sources
Severity
6.7MEDIUM
EPSS
0.1%
top 78.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 31
Latest updateMay 24

Description

RabbitMQ versions 3.8.x prior to 3.8.7 are prone to a Windows-specific binary planting security vulnerability that allows for arbitrary code execution. An attacker with write privileges to the RabbitMQ installation directory and local access on Windows could carry out a local binary hijacking (planting) attack and execute arbitrary code.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9

Affected Packages3 packages

CVEListV5vmware_tanzu/rabbitmq3.73.7.28+1
NVDbroadcom/rabbitmq_server3.8.03.8.7

🔴Vulnerability Details

2
GHSA
GHSA-82gq-g626-8g5r: RabbitMQ versions 32022-05-24
CVEList
RabbitMQ arbitrary code execution using local binary planting2020-08-31

📋Vendor Advisories

1
Debian
CVE-2020-5419: rabbitmq-server - RabbitMQ versions 3.8.x prior to 3.8.7 are prone to a Windows-specific binary pl...2020
CVE-2020-5419 (MEDIUM CVSS 6.7) | RabbitMQ versions 3.8.x prior to 3. | cvebase.io