PT-2016-7860 · Pivotal+4 · Rabbitmq+3

CVE-2016-9877

·

Publicado

2016-12-29

·

Atualizado

2025-04-02

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pivotal RabbitMQ versions 3.x through 3.5.7 Pivotal RabbitMQ versions 3.6.x through 3.6.5 RabbitMQ for PCF versions 1.5.x through 1.5.19 RabbitMQ for PCF versions 1.6.x through 1.6.11 RabbitMQ for PCF versions 1.7.x through 1.7.6
Description An issue was discovered where MQTT connection authentication with a username/password pair succeeds even if the password is omitted from the connection request, provided an existing username is given. This issue does not affect connections that use TLS with a client-provided certificate.
Recommendations For Pivotal RabbitMQ versions 3.x through 3.5.7, update to version 3.5.8 or later. For Pivotal RabbitMQ versions 3.6.x through 3.6.5, update to version 3.6.6 or later. For RabbitMQ for PCF versions 1.5.x through 1.5.19, update to version 1.5.20 or later. For RabbitMQ for PCF versions 1.6.x through 1.6.11, update to version 1.6.12 or later. For RabbitMQ for PCF versions 1.7.x through 1.7.6, update to version 1.7.7 or later.

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-1311
ALT-PU-2017-2710
CVE-2016-9877
DSA-3761-1
OPENSUSE-SU-2017_0306-1
OPENSUSE-SU-2024:11294-1
USN-3374-1

Produtos afetados

Alt Linux
Rabbitmq
Suse
Ubuntu