The Management plugin in RabbitMQ before 3.6.1 allows remote authenticated users with certain privileges to cause a denial of service (resource consumption) via the (1) lengths_age or (2) lengths_incr parameter.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Solaris | Oracle | 11.3 (including) | 11.3 (including) |
| Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6 | RedHat | rabbitmq-server-0:3.1.5-7.el6ost | * |
| Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7 | RedHat | rabbitmq-server-0:3.3.5-31.el7ost | * |
| Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7 | RedHat | rabbitmq-server-0:3.3.5-31.el7ost | * |
| Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 | RedHat | rabbitmq-server-0:3.3.5-31.el7ost | * |
| Red Hat OpenStack Platform 8.0 (Liberty) | RedHat | rabbitmq-server-0:3.3.5-30.el7ost | * |
| Rabbitmq-server | Ubuntu | esm-infra/xenial | * |
| Rabbitmq-server | Ubuntu | trusty | * |
| Rabbitmq-server | Ubuntu | xenial | * |
| Rabbitmq-server | Ubuntu | yakkety | * |