PT-2021-4577 · Rabbitmq+5 · Rabbitmq+5

Jonathan Knudsen

·

Published

2021-04-07

·

Updated

2024-06-19

·

CVE-2021-22116

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions RabbitMQ versions prior to 3.8.16
Description The issue is related to improper input validation in the AMQP 1.0 client connection endpoint, which can lead to a denial of service. A malicious user can exploit this by sending malicious AMQP messages to a RabbitMQ instance with the AMQP 1.0 plugin enabled.
Recommendations For versions prior to 3.8.16, update to version 3.8.16 or later to resolve the issue. As a temporary workaround, consider disabling the AMQP 1.0 plugin until a patch is available. Restrict access to the AMQP 1.0 client connection endpoint to minimize the risk of exploitation.

Exploit

Fix

DoS

Resource Exhaustion

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05248
BIT-RABBITMQ-2021-22116
CVE-2021-22116
DLA-2710-1
DLA-2710-2
MGASA-2021-0390
OPENSUSE-SU-2021:1334-1
OPENSUSE-SU-2021:3325-1
OPENSUSE-SU-2021_1334-1
OPENSUSE-SU-2021_3325-1
SUSE-FU-2024:2078-1
SUSE-SU-2021:3254-1
SUSE-SU-2021:3325-1
SUSE-SU-2021_3254-1
SUSE-SU-2021_3325-1
USN-5004-1

Affected Products

Astra Linux
Debian
Linuxmint
Rabbitmq
Suse
Ubuntu