Описание
RabbitMQ before 3.4.0 allows remote attackers to bypass the loopback_users restriction via a crafted X-Forwareded-For header.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse) | rabbitmq-server | Not affected | ||
| Red Hat Enterprise Linux OpenStack Platform 6 (Juno) | rabbitmq-server | Fix deferred |
Показывать по
10
Дополнительная информация
Статус:
Low
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1174872rabbitmq-server: insufficient 'X-Forwarded-For' header validation
3.6 Low
CVSS2
Связанные уязвимости
ubuntu
около 11 лет назад
RabbitMQ before 3.4.0 allows remote attackers to bypass the loopback_users restriction via a crafted X-Forwareded-For header.
nvd
около 11 лет назад
RabbitMQ before 3.4.0 allows remote attackers to bypass the loopback_users restriction via a crafted X-Forwareded-For header.
debian
около 11 лет назад
RabbitMQ before 3.4.0 allows remote attackers to bypass the loopback_u ...
github
больше 3 лет назад
RabbitMQ before 3.4.0 allows remote attackers to bypass the loopback_users restriction via a crafted X-Forwareded-For header.
3.6 Low
CVSS2