Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.1.10.2021.0390
Categoría:Mageia Linux Local Security Checks
Título:Mageia: Security Advisory (MGASA-2021-0390)
Resumen:The remote host is missing an update for the 'rabbitmq-server' package(s) announced via the MGASA-2021-0390 advisory.
Descripción:Summary:
The remote host is missing an update for the 'rabbitmq-server' package(s) announced via the MGASA-2021-0390 advisory.

Vulnerability Insight:
Updated rabbitmq-server packages fix security vulnerabilities:

RabbitMQ all versions prior to 3.8.16 are prone to a denial of service
vulnerability due to improper input validation in AMQP 1.0 client
connection endpoint. A malicious user can exploit the vulnerability by
sending malicious AMQP messages to the target RabbitMQ instance having
the AMQP 1.0 plugin enabled (CVE-2021-22116).

RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior
to version 3.8.17, a new user being added via management UI could lead
to the user's bane being rendered in a confirmation message without proper
'