PT-2019-6093 · Pivotal+4 · Rabbitmq+3
Mal
+1
·
Published
2019-11-22
·
Updated
2022-09-22
·
CVE-2019-11287
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Pivotal RabbitMQ versions 3.7.x prior to 3.7.21
Pivotal RabbitMQ versions 3.8.x prior to 3.8.1
RabbitMQ for Pivotal Platform versions 1.16.x prior to 1.16.7
RabbitMQ for Pivotal Platform versions 1.17.x prior to 1.17.4
Description
The issue is related to an error in the "X-Reason" HTTP header, which can be exploited to cause a denial of service attack. This can be achieved by inserting a malicious Erlang format string through the "X-Reason" HTTP Header, resulting in the server crashing due to heap consumption.
Recommendations
For Pivotal RabbitMQ versions 3.7.x prior to 3.7.21, update to version 3.7.21 or later.
For Pivotal RabbitMQ versions 3.8.x prior to 3.8.1, update to version 3.8.1 or later.
For RabbitMQ for Pivotal Platform versions 1.16.x prior to 1.16.7, update to version 1.16.7 or later.
For RabbitMQ for Pivotal Platform versions 1.17.x prior to 1.17.4, update to version 1.17.4 or later.
As a temporary workaround, consider restricting access to the web management plugin to minimize the risk of exploitation.
Exploit
Fix
DoS
Resource Exhaustion
Use of Externally-Controlled Format String
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linuxmint
Rabbitmq
Ubuntu