Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-51988

Опубликовано: 06 нояб. 2024
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 6.5

Описание

RabbitMQ is a feature rich, multi-protocol messaging and streaming broker. In affected versions queue deletion via the HTTP API was not verifying the configure permission of the user. Users who had all of the following: 1. Valid credentials, 2. Some permissions for the target virtual host & 3. HTTP API access. could delete queues it had no (deletion) permissions for. This issue has been addressed in version 3.12.11 of the open source rabbitMQ release and in versions 1.5.2, 3.13.0, and 4.0.0 of the tanzu release. Users are advised to upgrade. Users unable to upgrade may disable management plugin and use, for example, Prometheus and Grafana for monitoring.

РелизСтатусПримечание
devel

not-affected

3.12.1-1ubuntu2
esm-infra/bionic

not-affected

esm-infra/focal

not-affected

3.8.3-0ubuntu0.1
esm-infra/xenial

not-affected

focal

not-affected

3.8.3-0ubuntu0.1
jammy

not-affected

3.9.27-0ubuntu0.1
noble

not-affected

3.12.1-1ubuntu1
oracular

not-affected

3.12.1-1ubuntu2
upstream

released

3.12.11

Показывать по

EPSS

Процентиль: 34%
0.00133
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
redhat
около 1 года назад

RabbitMQ is a feature rich, multi-protocol messaging and streaming broker. In affected versions queue deletion via the HTTP API was not verifying the `configure` permission of the user. Users who had all of the following: 1. Valid credentials, 2. Some permissions for the target virtual host & 3. HTTP API access. could delete queues it had no (deletion) permissions for. This issue has been addressed in version 3.12.11 of the open source rabbitMQ release and in versions 1.5.2, 3.13.0, and 4.0.0 of the tanzu release. Users are advised to upgrade. Users unable to upgrade may disable management plugin and use, for example, Prometheus and Grafana for monitoring.

CVSS3: 6.5
nvd
около 1 года назад

RabbitMQ is a feature rich, multi-protocol messaging and streaming broker. In affected versions queue deletion via the HTTP API was not verifying the `configure` permission of the user. Users who had all of the following: 1. Valid credentials, 2. Some permissions for the target virtual host & 3. HTTP API access. could delete queues it had no (deletion) permissions for. This issue has been addressed in version 3.12.11 of the open source rabbitMQ release and in versions 1.5.2, 3.13.0, and 4.0.0 of the tanzu release. Users are advised to upgrade. Users unable to upgrade may disable management plugin and use, for example, Prometheus and Grafana for monitoring.

CVSS3: 6.5
debian
около 1 года назад

RabbitMQ is a feature rich, multi-protocol messaging and streaming bro ...

CVSS3: 6.5
github
около 1 года назад

RabbitMQ HTTP API's queue deletion endpoint does not verify that the user has a required permission

EPSS

Процентиль: 34%
0.00133
Низкий

6.5 Medium

CVSS3