PT-2021-20850 · Arm+1 · Arm+1
Published
2021-10-21
·
Updated
2021-10-28
·
CVE-2021-35227
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
ARM version 2020.2.6
Description:
The HTTP interface was enabled for RabbitMQ Plugin in ARM, and the ability to configure HTTPS was not available.
Recommendations:
For ARM version 2020.2.6, consider disabling the HTTP interface for the RabbitMQ Plugin until a configuration option for HTTPS is made available. Restrict access to the RabbitMQ Plugin to minimize the risk of exploitation.
Fix
Deserialization of Untrusted Data
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Arm
Rabbitmq Plugin