Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w6cq-9cf4-gqpg

Опубликовано: 23 окт. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 4.9

Описание

Denial of Service by publishing large messages over the HTTP API

Summary

Responsibly disclosed by @NSEcho.

HTTP API did not enforce an HTTP request body limit, making it vulnerable for DoS attacks with very large messages.

Details

An authenticated user with sufficient credentials can publish a very large messages over the HTTP API and cause target node to be terminated by an "out-of-memory killer"-like mechanism.

A PoC was provided to Team RabbitMQ privately.

Impact

Denial of Service

Пакеты

Наименование

rabbitmq

vmware
Затронутые версииВерсия исправления

>= 3.12.0, < 3.12.7

3.12.7

Наименование

rabbitmq

vmware
Затронутые версииВерсия исправления

>= 3.11.0, < 3.11.24

3.11.24

EPSS

Процентиль: 61%
0.01077
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 4.9
ubuntu
почти 3 года назад

RabbitMQ is a multi-protocol messaging and streaming broker. HTTP API did not enforce an HTTP request body limit, making it vulnerable for denial of service (DoS) attacks with very large messages. An authenticated user with sufficient credentials can publish a very large messages over the HTTP API and cause target node to be terminated by an "out-of-memory killer"-like mechanism. This vulnerability has been patched in versions 3.11.24 and 3.12.7.

CVSS3: 4.9
redhat
почти 3 года назад

RabbitMQ is a multi-protocol messaging and streaming broker. HTTP API did not enforce an HTTP request body limit, making it vulnerable for denial of service (DoS) attacks with very large messages. An authenticated user with sufficient credentials can publish a very large messages over the HTTP API and cause target node to be terminated by an "out-of-memory killer"-like mechanism. This vulnerability has been patched in versions 3.11.24 and 3.12.7.

CVSS3: 4.9
nvd
почти 3 года назад

RabbitMQ is a multi-protocol messaging and streaming broker. HTTP API did not enforce an HTTP request body limit, making it vulnerable for denial of service (DoS) attacks with very large messages. An authenticated user with sufficient credentials can publish a very large messages over the HTTP API and cause target node to be terminated by an "out-of-memory killer"-like mechanism. This vulnerability has been patched in versions 3.11.24 and 3.12.7.

CVSS3: 4.9
msrc
около 2 лет назад

Описание отсутствует

CVSS3: 4.9
debian
почти 3 года назад

RabbitMQ is a multi-protocol messaging and streaming broker. HTTP API ...

EPSS

Процентиль: 61%
0.01077
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-400