VendorsPivotal Softwarerabbitmqall versions
Vulnerabilities

Pivotal Software RabbitMQ

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2016-9877
An issue was discovered in Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before 3.6.6 and RabbitMQ for PCF 1.5.x before 1.5.20, 1.6.x before 1.6.12, and 1.7.x before 1.7.7. MQTT (MQ Telemetry Transport) connection authentication with a username/password pair succeeds if an existing username is provided but the password is omitted from the connection request. Connections that use TLS with a client-provided certificate are not affected.
Published 2016-12-29 · Modified
9.8EPSS 0.014
CVE-2018-1279
RabbitMQ cluster compromise due to deterministically generated cookie
Published 2018-12-10 · Modified
8.5EPSS 0.018
CVE-2017-4966
An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to 1.6.18, and 1.7.x versions prior to 1.7.15. RabbitMQ management UI stores signed-in user credentials in a browser's local storage without expiration, making it possible to retrieve them using a chained attack.
Published 2017-06-13 · Modified
7.8EPSS 0.004
CVE-2019-11287
RabbitMQ Web Management Plugin DoS via heap overflow
Published 2019-11-22 · Modified
7.5EPSS 0.044
CVE-2016-0929
The metrics-collection component in RabbitMQ for Pivotal Cloud Foundry (PCF) 1.6.x before 1.6.4 logs command lines of failed commands, which might allow context-dependent attackers to obtain sensitive information by reading the log data, as demonstrated by a syslog message that contains credentials from a command line.
Published 2016-09-18 · Modified
7.5EPSS 0.011
CVE-2015-8786
The Management plugin in RabbitMQ before 3.6.1 allows remote authenticated users with certain privileges to cause a denial of service (resource consumption) via the (1) lengths_age or (2) lengths_incr parameter.
Published 2016-12-09 · Modified
6.8EPSS 0.035
CVE-2020-5419
RabbitMQ arbitrary code execution using local binary planting
Published 2020-08-31 · Modified
6.7EPSS 0.005
CVE-2017-4965
An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to 1.6.18, and 1.7.x versions prior to 1.7.15. Several forms in the RabbitMQ management UI are vulnerable to XSS attacks.
Published 2017-06-13 · Modified
6.1EPSS 0.033
CVE-2017-4967
An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to 1.6.18, and 1.7.x versions prior to 1.7.15. Several forms in the RabbitMQ management UI are vulnerable to XSS attacks.
Published 2017-06-13 · Modified
6.1EPSS 0.019
CVE-2014-9494
RabbitMQ before 3.4.0 allows remote attackers to bypass the loopback_users restriction via a crafted X-Forwareded-For header.
Published 2015-01-20 · Modified
5.0EPSS 0.014
CVE-2019-11281
RabbitMQ XSS attack
Published 2019-10-16 · Modified
4.8EPSS 0.012