FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

RabbitMQ -- Denial of Service via improper input validation

Affected packages
rabbitmq < 3.8.16

Details

VuXML ID 7003b62d-7252-46ff-a9df-1b1900f1e65b
Discovery 2021-05-10
Entry 2021-06-28

Jonathon Knudsen of Synopsys Cybersecurity Research Center reports:

All versions prior to 3.8.16 are prone to a denial of service vulnerability due to improper input validation in AMQP 1.0 client connection endpoint. A malicious client can exploit the vulnerability by sending malicious AMQP messages to the target RabbitMQ instance having the AMQP 1.0 plugin enabled.

References

CVE Name CVE-2021-22116
URL https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22116
URL https://tanzu.vmware.com/security/cve-2021-22116