Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2019-11287— RabbitMQ Web Management Plugin DoS via heap overflow

EPSS 4.60% · P89
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2019-11287

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
RabbitMQ Web Management Plugin DoS via heap overflow
Source: NVD (National Vulnerability Database)
Vulnerability Description
Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is vulnerable to a denial of service attack. The "X-Reason" HTTP Header can be leveraged to insert a malicious Erlang format string that will expand and consume the heap, resulting in the server crashing.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
未加控制的资源消耗(资源穷尽)
Source: NVD (National Vulnerability Database)
Vulnerability Title
Pivotal Software RabbitMQ 格式化字符串错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Pivotal Software RabbitMQ是美国Pivotal Software公司的一套实现了高级消息队列协议(AMQP)的开源消息代理软件。 Pivotal Software RabbitMQ中的Web管理插件存在安全漏洞。攻击者可通过插入恶意的Erlang格式化字符串利用该漏洞造成服务器崩溃。以下产品及版本受到影响:Pivotal Software RabbitMQ 3.7.21之前的3.7.x版本,3.8.1之前的3.8.x版本;RabbitMQ for Pivotal Platform
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
PivotalRabbitMQ for Pivotal Platform 1.16 ~ 1.16.7 -
PivotalRabbitMQ 3.7 ~ v3.7.21 -

II. Public POCs for CVE-2019-11287

#POC DescriptionSource LinkShenlong Link
1CVE-2019-11287: DoS via Heap Overflow in RabbitMQ Web Management Pluginhttps://github.com/mbadanoiu/CVE-2019-11287POC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2019-11287

Please Login to view more intelligence information

IV. Related Vulnerabilities

V. Comments for CVE-2019-11287

No comments yet


Leave a comment