Описание
The Management plugin in RabbitMQ before 3.6.1 allows remote authenticated users with certain privileges to cause a denial of service (resource consumption) via the (1) lengths_age or (2) lengths_incr parameter.
A resource-consumption flaw was found in RabbitMQ Server, where the lengths_age or lengths_incr parameters were not validated in the management plugin. Remote, authenticated users with certain privileges could exploit this flaw to cause a denial of service by passing values which were too large.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenStack Platform 10 (Newton) | rabbitmq-server | Not affected | ||
| Red Hat OpenStack Platform 11 (Ocata) | rabbitmq-server | Not affected | ||
| Red Hat OpenStack Platform 9 (Mitaka) | rabbitmq-server | Not affected | ||
| Red Hat Storage Console 2 | rabbitmq-server | Will not fix | ||
| Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6 | rabbitmq-server | Fixed | RHSA-2017:0533 | 15.03.2017 |
| Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7 | rabbitmq-server | Fixed | RHSA-2017:0532 | 15.03.2017 |
| Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 | rabbitmq-server | Fixed | RHSA-2017:0531 | 15.03.2017 |
| Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 | rabbitmq-server | Fixed | RHSA-2017:0530 | 15.03.2017 |
| Red Hat OpenStack Platform 8.0 (Liberty) | rabbitmq-server | Fixed | RHSA-2017:0226 | 01.02.2017 |
Показывать по
Дополнительная информация
Статус:
6.5 Medium
CVSS3
6.3 Medium
CVSS2
Связанные уязвимости
The Management plugin in RabbitMQ before 3.6.1 allows remote authenticated users with certain privileges to cause a denial of service (resource consumption) via the (1) lengths_age or (2) lengths_incr parameter.
The Management plugin in RabbitMQ before 3.6.1 allows remote authenticated users with certain privileges to cause a denial of service (resource consumption) via the (1) lengths_age or (2) lengths_incr parameter.
The Management plugin in RabbitMQ before 3.6.1 allows remote authentic ...
The Management plugin in RabbitMQ before 3.6.1 allows remote authenticated users with certain privileges to cause a denial of service (resource consumption) via the (1) lengths_age or (2) lengths_incr parameter.
6.5 Medium
CVSS3
6.3 Medium
CVSS2