RabbitMQ Web Management Plugin DoS via heap overflow
Published Nov 22, 2019
7.5
HIGHCVSS 3.1
EPSS 4.40%
Description
Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is vulnerable to a denial of service attack. The "X-Reason" HTTP Header can be leveraged to insert a malicious Erlang format string that will expand and consume the heap, resulting in the server crashing.
Affected products
-
- Version 3.7StatusaffectedConstraints<v3.7.21
- Version 3.8StatusaffectedConstraints<v3.8.1
- Version
-
- Version 1.16StatusaffectedConstraints<1.16.7
- Version 1.17StatusaffectedConstraints<1.17.4
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Pivotal | RabbitMQ | n/a |
| |||||||||
| Pivotal | RabbitMQ for Pivotal Platform | n/a |
|
Configuration 1
- ≥ 3.8.0 · < 3.8.1
- ≥ 1.16.0 · < 1.16.7
- ≥ 1.17.0 · < 1.17.4
- ≥ 3.7.0 · < 3.7.21
Configuration 2
- 30
- 31
Configuration 4
- 9.0
No data.
Red Hat OpenStack Platform 15.0 (Stein)
rabbitmq-server-0:3.7.22-1.el8ost
Fixed · RHSA-2020:0078
CloudForms Management Engine 5
rabbitmq-server
Not affected
Red Hat Ansible Tower 3
rabbitmq-server
Not affected
Red Hat OpenStack Platform 10 (Newton)
rabbitmq-server
Out of support scope
Red Hat OpenStack Platform 13 (Queens)
rabbitmq-server
Not affected
Red Hat OpenStack Platform 14 (Rocky)
rabbitmq-server
Out of support scope
Red Hat OpenStack Platform 16 (Train)
rabbitmq-server
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenStack Platform 15.0 (Stein) | rabbitmq-server-0:3.7.22-1.el8ost | Fixed | RHSA-2020:0078 |
| CloudForms Management Engine 5 | rabbitmq-server | Not affected | n/a |
| Red Hat Ansible Tower 3 | rabbitmq-server | Not affected | n/a |
| Red Hat OpenStack Platform 10 (Newton) | rabbitmq-server | Out of support scope | n/a |
| Red Hat OpenStack Platform 13 (Queens) | rabbitmq-server | Not affected | n/a |
| Red Hat OpenStack Platform 14 (Rocky) | rabbitmq-server | Out of support scope | n/a |
| Red Hat OpenStack Platform 16 (Train) | rabbitmq-server | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Ansible Tower and Red Hat CloudForms are not vulnerable as they do not expose the RabbitMQ management interface by default. In Red Hat OpenStack Platform 13, the management interface was not enabled by default. So, although the flaw code was packaged, its impact for this version has been lowered to Moderate.
Red Hat mitigation
This flaw can be mitigated by disabling the Web Management plugin: rabbitmq-plugins disable rabbitmq_management.
References (13)
- https://access.redhat.com/errata/RHSA-2020:0078 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-11287 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1783318 Issue Tracking
- https://github.com/DrunkenShells/Disclosures/tree/master/CVE-2019-11287-DoS%20via%20Heap%20Overflow-RabbitMQ%20Web%20Management%20Plugin x_refsource_MISCExploitThird Party Advisory
- https://github.com/advisories/GHSA-hrfh-7j5f-8ccr Advisory
- https://lists.debian.org/debian-lts-announce/2021/07/msg00011.html mailing-listx_refsource_MLISTThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EEQ6O7PMNJKYFMQYHAB55L423GYK63SO/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PYTGR3D5FW2O25RXZOTIZMOD2HAUVBE4/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EEQ6O7PMNJKYFMQYHAB55L423GYK63SO
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PYTGR3D5FW2O25RXZOTIZMOD2HAUVBE4
- https://nvd.nist.gov/vuln/detail/CVE-2019-11287
- https://pivotal.io/security/cve-2019-11287 x_refsource_CONFIRMVendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-11287
Change history (0)
No recorded changes yet.