RabbitMQ all versions prior to 3.8.16 are prone to a denial of service vulnerability due to improper input validation in AMQP 1.0 client connection endpoint. A malicious user can exploit the vulnerability by sending malicious AMQP messages to the target RabbitMQ instance having the AMQP 1.0 plugin enabled.
References
Link | Resource |
---|---|
https://lists.debian.org/debian-lts-announce/2021/07/msg00011.html | Mailing List Third Party Advisory |
https://tanzu.vmware.com/security/cve-2021-22116 | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: vmware
Published: 2021-06-08T11:23:58
Updated: 2021-07-19T19:06:20
Reserved: 2021-01-04T00:00:00
Link: CVE-2021-22116
JSON object: View
NVD Information
Status : Analyzed
Published: 2021-06-08T12:15:10.347
Modified: 2022-10-25T16:33:02.987
Link: CVE-2021-22116
JSON object: View
Redhat Information
No data.