PT-2021-20850 · Arm+1 · Arm+1

Published

2021-10-21

·

Updated

2021-10-28

·

CVE-2021-35227

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: ARM version 2020.2.6
Description: The HTTP interface was enabled for RabbitMQ Plugin in ARM, and the ability to configure HTTPS was not available.
Recommendations: For ARM version 2020.2.6, consider disabling the HTTP interface for the RabbitMQ Plugin until a configuration option for HTTPS is made available. Restrict access to the RabbitMQ Plugin to minimize the risk of exploitation.

Fix

Deserialization of Untrusted Data

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-35227

Affected Products

Arm
Rabbitmq Plugin