Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-51988

Опубликовано: 06 нояб. 2024
Источник: ubuntu
Приоритет: medium
CVSS3: 6.5

Описание

RabbitMQ is a feature rich, multi-protocol messaging and streaming broker. In affected versions queue deletion via the HTTP API was not verifying the configure permission of the user. Users who had all of the following: 1. Valid credentials, 2. Some permissions for the target virtual host & 3. HTTP API access. could delete queues it had no (deletion) permissions for. This issue has been addressed in version 3.12.11 of the open source rabbitMQ release and in versions 1.5.2, 3.13.0, and 4.0.0 of the tanzu release. Users are advised to upgrade. Users unable to upgrade may disable management plugin and use, for example, Prometheus and Grafana for monitoring.

РелизСтатусПримечание
devel

not-affected

3.12.1-1ubuntu2
esm-infra/bionic

not-affected

esm-infra/focal

not-affected

3.8.3-0ubuntu0.1
esm-infra/xenial

not-affected

focal

not-affected

3.8.3-0ubuntu0.1
jammy

not-affected

3.9.27-0ubuntu0.1
noble

not-affected

3.12.1-1ubuntu1
oracular

not-affected

3.12.1-1ubuntu2
upstream

released

3.12.11

Показывать по

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
redhat
больше 1 года назад

RabbitMQ is a feature rich, multi-protocol messaging and streaming broker. In affected versions queue deletion via the HTTP API was not verifying the `configure` permission of the user. Users who had all of the following: 1. Valid credentials, 2. Some permissions for the target virtual host & 3. HTTP API access. could delete queues it had no (deletion) permissions for. This issue has been addressed in version 3.12.11 of the open source rabbitMQ release and in versions 1.5.2, 3.13.0, and 4.0.0 of the tanzu release. Users are advised to upgrade. Users unable to upgrade may disable management plugin and use, for example, Prometheus and Grafana for monitoring.

CVSS3: 6.5
nvd
больше 1 года назад

RabbitMQ is a feature rich, multi-protocol messaging and streaming broker. In affected versions queue deletion via the HTTP API was not verifying the `configure` permission of the user. Users who had all of the following: 1. Valid credentials, 2. Some permissions for the target virtual host & 3. HTTP API access. could delete queues it had no (deletion) permissions for. This issue has been addressed in version 3.12.11 of the open source rabbitMQ release and in versions 1.5.2, 3.13.0, and 4.0.0 of the tanzu release. Users are advised to upgrade. Users unable to upgrade may disable management plugin and use, for example, Prometheus and Grafana for monitoring.

CVSS3: 6.5
debian
больше 1 года назад

RabbitMQ is a feature rich, multi-protocol messaging and streaming bro ...

CVSS3: 6.5
github
больше 1 года назад

RabbitMQ HTTP API's queue deletion endpoint does not verify that the user has a required permission

6.5 Medium

CVSS3