Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-5419

Опубликовано: 31 авг. 2020
Источник: nvd
CVSS3: 6.7
CVSS3: 6.7
CVSS2: 4.6
EPSS Низкий

Описание

RabbitMQ versions 3.8.x prior to 3.8.7 are prone to a Windows-specific binary planting security vulnerability that allows for arbitrary code execution. An attacker with write privileges to the RabbitMQ installation directory and local access on Windows could carry out a local binary hijacking (planting) attack and execute arbitrary code.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:broadcom:rabbitmq_server:*:*:*:*:*:*:*:*
Версия от 3.8.0 (включая) до 3.8.7 (исключая)
cpe:2.3:a:pivotal_software:rabbitmq:*:*:*:*:*:*:*:*
Версия до 3.7.28 (исключая)

EPSS

Процентиль: 22%
0.0007
Низкий

6.7 Medium

CVSS3

6.7 Medium

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-427
CWE-427

Связанные уязвимости

CVSS3: 6.7
ubuntu
больше 5 лет назад

RabbitMQ versions 3.8.x prior to 3.8.7 are prone to a Windows-specific binary planting security vulnerability that allows for arbitrary code execution. An attacker with write privileges to the RabbitMQ installation directory and local access on Windows could carry out a local binary hijacking (planting) attack and execute arbitrary code.

CVSS3: 6.7
debian
больше 5 лет назад

RabbitMQ versions 3.8.x prior to 3.8.7 are prone to a Windows-specific ...

CVSS3: 6.7
github
больше 3 лет назад

RabbitMQ versions 3.8.x prior to 3.8.7 are prone to a Windows-specific binary planting security vulnerability that allows for arbitrary code execution. An attacker with write privileges to the RabbitMQ installation directory and local access on Windows could carry out a local binary hijacking (planting) attack and execute arbitrary code.

EPSS

Процентиль: 22%
0.0007
Низкий

6.7 Medium

CVSS3

6.7 Medium

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-427
CWE-427