RabbitMQ installers on Windows prior to version 3.8.16 do not harden plugin directory permissions, potentially allowing attackers with sufficient local filesystem permissions to add arbitrary plugins.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Oracle Solaris | — | Upgrade runtime/erlang to version 24.0.2-11.4.39.0.1.107.0 on Solaris 11.4Upgrade network/amqp/rabbitmq to version 3.8.18-11.4.39.0.1.107.0 on Solaris 11.4Upgrade runtime/elixir to version 1.12.1-11.4.39.0.1.107.0 on Solaris 11.4Upgrade runtime/erlang/documentation to version 24.0.2-11.4.39.0.1.107.0 on Solaris 11.4Upgrade developer/elixir/hex to version 0.21.2-11.4.39.0.1.107.0 on Solaris 11.4 | Nov 17, 2021 | May 18, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub