RabbitMQ cluster compromise due to deterministically generated cookie
Published Dec 10, 2018
8.5
HIGHCVSS 3.0
EPSS 1.83%
Description
Pivotal RabbitMQ for PCF, all versions, uses a deterministically generated cookie that is shared between all machines when configured in a multi-tenant cluster. A remote attacker who can gain information about the network topology can guess this cookie and, if they have access to the right ports on any server in the MQ cluster can use this cookie to gain full control over the entire cluster.
Affected products
-
- Version 1StatusaffectedConstraints<all versions*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Pivotal | RabbitMq for PCF | n/a |
|
- n/a
No data.
CloudForms Management Engine 5
rabbitmq-server
Not affected
Red Hat Ansible Tower 3
rabbitmq-server
Not affected
Red Hat OpenStack Platform 10 (Newton)
rabbitmq-server
Out of support scope
Red Hat OpenStack Platform 13 (Queens)
rabbitmq-server
Will not fix
Red Hat OpenStack Platform 14 (Rocky)
rabbitmq-server
Out of support scope
Red Hat OpenStack Platform 8 (Liberty)
rabbitmq-server
Out of support scope
Red Hat OpenStack Platform 9 (Mitaka)
rabbitmq-server
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| CloudForms Management Engine 5 | rabbitmq-server | Not affected | n/a |
| Red Hat Ansible Tower 3 | rabbitmq-server | Not affected | n/a |
| Red Hat OpenStack Platform 10 (Newton) | rabbitmq-server | Out of support scope | n/a |
| Red Hat OpenStack Platform 13 (Queens) | rabbitmq-server | Will not fix | n/a |
| Red Hat OpenStack Platform 14 (Rocky) | rabbitmq-server | Out of support scope | n/a |
| Red Hat OpenStack Platform 8 (Liberty) | rabbitmq-server | Out of support scope | n/a |
| Red Hat OpenStack Platform 9 (Mitaka) | rabbitmq-server | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
OpenShift Online: RabbitMQ is only used by the Ansible Tower, which is not a standard part of the OpenShift product, however is deployed as a management tool. This is set as deferred as it has no impact to customers and is not deployed in a clustered configuration. A cluster using an Erlang-generated cookie would be required for cookie guessing to provide and environmental leverage. OpenStack: For RHOSP10+, the rabbit cookie is set to a random string during deployment, rather than relying on Erlang to generate the cookie, if the cookie has not been overridden in the deployment configuration. In either case, this avoids the predictable Erlang cookie generation highlighted by this flaw, meaning RHOSP10+ is not vulnerable. Further mitigating the flaw, is the fact that RabbitMQ, in an OpenStack context, is deployed to the admin network and as such should only be accessible to OpenStack services, not public users via an external network. For RHOSP8+9, when deployed with Director (TripleO), the RabbitMQ salt is initialized via the Heat RandomString function, also bypassing this vulnerability. RHOSP8+9 however did not use Director as the default deployment mechanism. When installing RHOSP manually in these versions, our installation documentation does not provide guidance for configuring clustered RabbitMQ. It is safe to assume that some customers may have this configured in an insecure way, despite the fact that we would not have told them how to install and configure a cluster in a vulnerable way. Ansible Tower: In Tower we do not use the programmatic cookie generation that gives rise to this vulnerability. Instead we use cookiemonster. So this issue does not affect Ansible Tower. CloudForms (CFME): RabbitMQ shipped with CloudForms is exclusively used by Ansible Tower. Since Ansible Tower is not vulnerable, due to the reasons described above, then CloudForms isn't, as well.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
1 other source (CVE.org) ▾
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
AV:A/AC:L/Au:N/C:P/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v5
Table of values (13 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.83% (0.01830) | 78.09th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.83% (0.01830) | 76.00th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.13% (0.00128) | 48.12th | v3 (v2023.03.01) |
| Jun 14, 2024 | 0.13% (0.00128) | 47.81th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.13% (0.00128) | 45.80th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.05% (0.01055) | 52.13th | v2 (v2022.01.01) |
| Sep 17, 2022 | 1.05% (0.01055) | 50.47th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.05% (0.01055) | 48.43th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.05% (0.01055) | 27.52th | v2 (v2022.01.01) |
| Feb 3, 2022 | 0.52% (0.00523) | 12.55th | v1 |
| Jan 6, 2022 | 0.52% (0.00523) | 12.10th | v1 |
| Sep 1, 2021 | 0.52% (0.00523) | 32.27th | v1 |
| Apr 14, 2021 | 0.52% (0.00523) | 0.00th | v1 |
References (5)
- https://access.redhat.com/security/cve/CVE-2018-1279 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1661092 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2018-1279
- https://pivotal.io/security/cve-2018-1279 x_refsource_CONFIRMMitigationVendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2018-1279
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2018-1279 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1661092 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-1279 | ||
| https://pivotal.io/security/cve-2018-1279 | x_refsource_CONFIRMMitigationVendor Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2018-1279 |
Change history (0)
No recorded changes yet.