Back

HIGH

RabbitMQ Web Management Plugin DoS via heap overflow

Published Nov 22, 2019

Description

Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is vulnerable to a denial of service attack. The "X-Reason" HTTP Header can be leveraged to insert a malicious Erlang format string that will expand and consume the heap, resulting in the server crashing.

Affected products

Remediation

Red Hat statement

Red Hat Ansible Tower and Red Hat CloudForms are not vulnerable as they do not expose the RabbitMQ management interface by default. In Red Hat OpenStack Platform 13, the management interface was not enabled by default. So, although the flaw code was packaged, its impact for this version has been lowered to Moderate.

Red Hat mitigation

This flaw can be mitigated by disabling the Web Management plugin: rabbitmq-plugins disable rabbitmq_management.

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner pivotal
Published Nov 22, 2019
Updated Sep 16, 2024
Reserved Apr 18, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Dec 13, 2019
GHSA-HRFH-7J5F-8CCR