Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.10.2021.0390
Category:Mageia Linux Local Security Checks
Title:Mageia: Security Advisory (MGASA-2021-0390)
Summary:The remote host is missing an update for the 'rabbitmq-server' package(s) announced via the MGASA-2021-0390 advisory.
Description:Summary:
The remote host is missing an update for the 'rabbitmq-server' package(s) announced via the MGASA-2021-0390 advisory.

Vulnerability Insight:
Updated rabbitmq-server packages fix security vulnerabilities:

RabbitMQ all versions prior to 3.8.16 are prone to a denial of service
vulnerability due to improper input validation in AMQP 1.0 client
connection endpoint. A malicious user can exploit the vulnerability by
sending malicious AMQP messages to the target RabbitMQ instance having
the AMQP 1.0 plugin enabled (CVE-2021-22116).

RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior
to version 3.8.17, a new user being added via management UI could lead
to the user's bane being rendered in a confirmation message without proper
'