Description
Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is vulnerable to a denial of service attack. The "X-Reason" HTTP Header can be leveraged to insert a malicious Erlang format string that will expand and consume the heap, resulting in the server crashing.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2710-1 | rabbitmq-server security update |
EUVD |
EUVD-2022-4206 | Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is vulnerable to a denial of service attack. The "X-Reason" HTTP Header can be leveraged to insert a malicious Erlang format string that will expand and consume the heap, resulting in the server crashing. |
Github GHSA |
GHSA-hrfh-7j5f-8ccr | Pivotal RabbitMQ is vulnerable to a denial of service attack |
Ubuntu USN |
USN-5004-1 | RabbitMQ vulnerabilities |
References
History
Wed, 02 Apr 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Broadcom
Broadcom rabbitmq Server |
|
| CPEs | cpe:2.3:a:broadcom:rabbitmq_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Vmware
Vmware rabbitmq |
Broadcom
Broadcom rabbitmq Server |
Status: PUBLISHED
Assigner: pivotal
Published:
Updated: 2024-09-16T22:24:51.121Z
Reserved: 2019-04-18T00:00:00.000Z
Link: CVE-2019-11287
No data.
Status : Modified
Published: 2019-11-23T00:15:10.683
Modified: 2025-04-02T14:13:43.180
Link: CVE-2019-11287
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Github GHSA
Ubuntu USN