Pivotal Software Rabbitmq vulnerabilities

10 known vulnerabilities affecting pivotal_software/rabbitmq.

Total CVEs
10
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH3MEDIUM6

Vulnerabilities

Page 1 of 1
CVE-2020-5419MEDIUMCVSS 6.7fixed in 3.7.282020-08-31
CVE-2020-5419 [MEDIUM] CWE-427 CVE-2020-5419: RabbitMQ versions 3.8.x prior to 3.8.7 are prone to a Windows-specific binary planting security vuln RabbitMQ versions 3.8.x prior to 3.8.7 are prone to a Windows-specific binary planting security vulnerability that allows for arbitrary code execution. An attacker with write privileges to the RabbitMQ installation directory and local access on Windows could carry out a local binary hijacking (planting) attack and execute arbitrary code.
nvd
CVE-2019-11287HIGHCVSS 7.5≥ 1.16.0, < 1.16.7≥ 1.17.0, < 1.17.4+1 more2019-11-23
CVE-2019-11287 [HIGH] CWE-400 CVE-2019-11287: Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is vulnerable to a denial of service attack. The "X-Reason" HTTP Header can be leveraged to insert a malicious Erlang format string that w
nvd
CVE-2019-11281MEDIUMCVSS 4.8fixed in 3.7.18≥ 1.15.0, < 1.15.13+2 more2019-10-16
CVE-2019-11281 [MEDIUM] CWE-79 CVE-2019-11281: Pivotal RabbitMQ, versions prior to v3.7.18, and RabbitMQ for PCF, versions 1.15.x prior to 1.15.13, Pivotal RabbitMQ, versions prior to v3.7.18, and RabbitMQ for PCF, versions 1.15.x prior to 1.15.13, versions 1.16.x prior to 1.16.6, and versions 1.17.x prior to 1.17.3, contain two components, the virtual host limits page, and the federation management UI, which do not properly sanitize user input. A remote authenticated malicious user with adminis
nvd
CVE-2017-4966HIGHCVSS 7.8v3.5.4v3.5.5+55 more2017-06-13
CVE-2017-4966 [HIGH] CWE-200 CVE-2017-4966: An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to 1.6.18, and 1.7.x versions prior to 1.7.15. RabbitMQ management UI stores signed-in user credentials in a browser's local storage without ex
nvd
CVE-2017-4967MEDIUMCVSS 6.1v3.5.4v3.5.5+55 more2017-06-13
CVE-2017-4967 [MEDIUM] CWE-79 CVE-2017-4967: An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to 1.6.18, and 1.7.x versions prior to 1.7.15. Several forms in the RabbitMQ management UI are vulnerable to XSS attacks.
nvd
CVE-2017-4965MEDIUMCVSS 6.1v3.5.4v3.5.5+55 more2017-06-13
CVE-2017-4965 [MEDIUM] CWE-79 CVE-2017-4965: An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to 1.6.18, and 1.7.x versions prior to 1.7.15. Several forms in the RabbitMQ management UI are vulnerable to XSS attacks.
nvd
CVE-2016-9877CRITICALCVSS 9.8v3.5.4v3.5.5+42 more2016-12-29
CVE-2016-9877 [CRITICAL] CWE-284 CVE-2016-9877: An issue was discovered in Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before 3.6.6 and RabbitMQ for An issue was discovered in Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before 3.6.6 and RabbitMQ for PCF 1.5.x before 1.5.20, 1.6.x before 1.6.12, and 1.7.x before 1.7.7. MQTT (MQ Telemetry Transport) connection authentication with a username/password pair succeeds if an existing username is provided but the password is omitted from the connection r
nvd
CVE-2015-8786MEDIUMCVSS 6.5v3.6.02016-12-09
CVE-2015-8786 [MEDIUM] CWE-399 CVE-2015-8786: The Management plugin in RabbitMQ before 3.6.1 allows remote authenticated users with certain privil The Management plugin in RabbitMQ before 3.6.1 allows remote authenticated users with certain privileges to cause a denial of service (resource consumption) via the (1) lengths_age or (2) lengths_incr parameter.
nvd
CVE-2016-0929HIGHCVSS 7.5v1.6.0v1.6.1+2 more2016-09-18
CVE-2016-0929 [HIGH] CWE-200 CVE-2016-0929: The metrics-collection component in RabbitMQ for Pivotal Cloud Foundry (PCF) 1.6.x before 1.6.4 logs The metrics-collection component in RabbitMQ for Pivotal Cloud Foundry (PCF) 1.6.x before 1.6.4 logs command lines of failed commands, which might allow context-dependent attackers to obtain sensitive information by reading the log data, as demonstrated by a syslog message that contains credentials from a command line.
nvd
CVE-2014-9494MEDIUMCVSS 5.0≤ 3.3.52015-01-20
CVE-2014-9494 [MEDIUM] CWE-264 CVE-2014-9494: RabbitMQ before 3.4.0 allows remote attackers to bypass the loopback_users restriction via a crafted RabbitMQ before 3.4.0 allows remote attackers to bypass the loopback_users restriction via a crafted X-Forwareded-For header.
nvd