PT-2019-6093 · Pivotal+4 · Rabbitmq+3

Mal

+1

·

Published

2019-11-22

·

Updated

2022-09-22

·

CVE-2019-11287

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Pivotal RabbitMQ versions 3.7.x prior to 3.7.21 Pivotal RabbitMQ versions 3.8.x prior to 3.8.1 RabbitMQ for Pivotal Platform versions 1.16.x prior to 1.16.7 RabbitMQ for Pivotal Platform versions 1.17.x prior to 1.17.4
Description The issue is related to an error in the "X-Reason" HTTP header, which can be exploited to cause a denial of service attack. This can be achieved by inserting a malicious Erlang format string through the "X-Reason" HTTP Header, resulting in the server crashing due to heap consumption.
Recommendations For Pivotal RabbitMQ versions 3.7.x prior to 3.7.21, update to version 3.7.21 or later. For Pivotal RabbitMQ versions 3.8.x prior to 3.8.1, update to version 3.8.1 or later. For RabbitMQ for Pivotal Platform versions 1.16.x prior to 1.16.7, update to version 1.16.7 or later. For RabbitMQ for Pivotal Platform versions 1.17.x prior to 1.17.4, update to version 1.17.4 or later. As a temporary workaround, consider restricting access to the web management plugin to minimize the risk of exploitation.

Exploit

Fix

DoS

Resource Exhaustion

Use of Externally-Controlled Format String

Weakness Enumeration

Related Identifiers

BDU:2021-05251
CVE-2019-11287
DLA-2710-1
DLA-2710-2
GHSA-HRFH-7J5F-8CCR
RHSA-2020:0078
SUSE-SU-2022:3338-1
SUSE-SU-2022:3339-1
USN-5004-1

Affected Products

Astra Linux
Linuxmint
Rabbitmq
Ubuntu