The Management plugin in RabbitMQ before 3.6.1 allows remote authenticated users with certain privileges to cause a denial of service (resource consumption) via the (1) lengths_age or (2) lengths_incr parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Solaris | Oracle | 11.3 (including) | 11.3 (including) |
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6 | RedHat | rabbitmq-server-0:3.1.5-7.el6ost | * |
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7 | RedHat | rabbitmq-server-0:3.3.5-31.el7ost | * |
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 | RedHat | rabbitmq-server-0:3.3.5-31.el7ost | * |
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 | RedHat | rabbitmq-server-0:3.3.5-31.el7ost | * |
Red Hat OpenStack Platform 8.0 (Liberty) | RedHat | rabbitmq-server-0:3.3.5-30.el7ost | * |
Rabbitmq-server | Ubuntu | esm-infra/xenial | * |
Rabbitmq-server | Ubuntu | trusty | * |
Rabbitmq-server | Ubuntu | xenial | * |
Rabbitmq-server | Ubuntu | yakkety | * |