PT-2021-3265 · Rabbitmq · Rabbitmq

Robert Chen

·

Published

2021-05-10

·

Updated

2024-03-06

·

CVE-2021-22117

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions RabbitMQ versions prior to 3.8.16
Description The issue is related to insufficient access control in the plugin directory of RabbitMQ installers on Windows. This could potentially allow attackers with sufficient local filesystem permissions to add arbitrary plugins, leading to the execution of arbitrary code.
Recommendations For versions prior to 3.8.16, update to version 3.8.16 or later to resolve the issue. As a temporary workaround, consider restricting access to the plugin directory to minimize the risk of exploitation.

Fix

Incorrect Permission

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2021-03003
BIT-RABBITMQ-2021-22117
CVE-2021-22117

Affected Products

Rabbitmq