漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
RabbitMQ management HTTP API accepts request bodies larger than configured max_http_body_size
Vulnerability Description
RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_management HTTP API accepts oversized valid JSON bodies on with_decode and direct_request paths because read_complete_body checks the accumulated size before the final chunk but not the final combined size. This issue is fixed in versions 3.13.14, 4.0.19, 4.1.10, and 4.2.5.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L
Vulnerability Type
不加限制或调节的资源分配
Vulnerability Title
rabbitmq-server 资源管理错误漏洞
Vulnerability Description
RabbitMQ rabbitmq-server是RabbitMQ组织的消息队列中间件。 rabbitmq-server存在资源管理错误漏洞,该漏洞源于rabbitmq_management HTTP API在读取完整JSON体时最终组合大小检查缺失,导致接受超大的有效JSON体。以下版本受到影响:3.13.14之前版本、4.0.19之前版本、4.1.10之前版本和4.2.5之前版本。
CVSS Information
N/A
Vulnerability Type
N/A