Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is vulnerable to a denial of service attack. The "X-Reason" HTTP Header can be leveraged to insert a malicious Erlang format string that will expand and consume the heap, resulting in the server crashing.
{
"unresolved_ranges": [
{
"cpe": "cpe:2.3:a:pivotal_software:rabbitmq:*:*:*:*:*:pivotal_cloud_foundry:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"introduced": "1.16.0"
},
{
"fixed": "1.16.7"
},
{
"introduced": "1.17.0"
},
{
"fixed": "1.17.4"
}
]
},
{
"cpe": "cpe:2.3:a:redhat:openstack:15:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "15"
}
]
},
{
"cpe": "cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "9.0"
}
]
},
{
"cpe": "cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "30"
}
]
},
{
"cpe": "cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "31"
}
]
}
]
}{
"cpe": [
"cpe:2.3:a:broadcom:rabbitmq_server:*:*:*:*:*:*:*:*",
"cpe:2.3:a:pivotal_software:rabbitmq:*:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"extracted_events": [
{
"introduced": "3.8.0"
},
{
"fixed": "3.8.1"
},
{
"introduced": "3.7.0"
},
{
"fixed": "3.7.21"
}
]
}