RabbitMQ versions 3.8.x prior to 3.8.7 are prone to a Windows-specific binary planting security vulnerability that allows for arbitrary code execution. An attacker with write privileges to the RabbitMQ installation directory and local access on Windows could carry out a local binary hijacking (planting) attack and execute arbitrary code.
CVSS Details
- CVSS 3.1 Base Score: 6.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Oracle Solaris | — | Upgrade network/amqp/rabbitmq to version 3.8.18-11.4.39.0.1.107.0 on Solaris 11.4Upgrade runtime/erlang to version 24.0.2-11.4.39.0.1.107.0 on Solaris 11.4Upgrade runtime/elixir to version 1.12.1-11.4.39.0.1.107.0 on Solaris 11.4Upgrade runtime/erlang/documentation to version 24.0.2-11.4.39.0.1.107.0 on Solaris 11.4Upgrade developer/elixir/hex to version 0.21.2-11.4.39.0.1.107.0 on Solaris 11.4 | Nov 17, 2021 | Aug 31, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub