PT-2023-8905 · Rabbitmq+5 · Rabbitmq+5

Nsecho

·

Published

2023-10-23

·

Updated

2024-06-19

·

CVE-2023-46118

CVSS v2.0

6.1

Medium

VectorAV:N/AC:L/Au:M/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions RabbitMQ versions prior to 3.11.24 RabbitMQ versions prior to 3.12.7
Description The issue is related to the HTTP API of RabbitMQ, a multi-protocol messaging and streaming broker, which did not enforce an HTTP request body limit. This made it vulnerable to denial of service (DoS) attacks with very large messages. An authenticated user with sufficient credentials can publish very large messages over the HTTP API, causing the target node to be terminated by an "out-of-memory killer"-like mechanism.
Recommendations For RabbitMQ versions prior to 3.11.24, update to version 3.11.24 or later to resolve the issue. For RabbitMQ versions prior to 3.12.7, update to version 3.12.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the HTTP API to minimize the risk of exploitation.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-32107
AZL-35196
BDU:2024-02584
BIT-RABBITMQ-2023-46118
CVE-2023-46118
DLA-3687-1
DSA-5571-1
GHSA-W6CQ-9CF4-GQPG
OPENSUSE-SU-2023_4939-1
RHSA-2024:0217
SUSE-FU-2024:2078-1
SUSE-SU-2023:4939-1
SUSE-SU-2023_4939-1
USN-6501-1

Affected Products

Astra Linux
Linuxmint
Rabbitmq
Red Os
Suse
Ubuntu