<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – RabbitMQ (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/rabbitmq.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/rabbitmq-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – RabbitMQ (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:34 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-9844 – Use of default credentials vulnerability in Roche Diagnostics navify Digital Pat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9844</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9844</guid>
    <pubDate>Tue, 02 Jun 2026 14:17:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9844</strong></p>
  <p>Use of default credentials vulnerability in Roche Diagnostics navify Digital Pathology (RabbitMQ Management interface modules) allows Default Usernames and Passwords. This issue affects navify Digital Pathology: from 2.0.0 before 2.4.1.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9844">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25112 – A high-severity vulnerability in the deployment of Genetec RabbitMQ that allows ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25112</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25112</guid>
    <pubDate>Tue, 26 May 2026 16:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25112</strong></p>
  <p>A high-severity vulnerability in the deployment of Genetec RabbitMQ that allows a privilege escalation attack.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25112">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9133 – Active debug code exists in the ARN resolver of amazon-mq rabbitmq-aws before ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9133</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9133</guid>
    <pubDate>Wed, 20 May 2026 20:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9133</strong></p>
  <p>Active debug code exists in the ARN resolver of amazon-mq rabbitmq-aws before version 0.2.1. A debug ARN scheme (arn:aws-debug:file) accepted by the PUT /api/aws/arn/validate validation endpoint might allow remote authenticated users to perform arbitrary file reads on any file accessible to the RabbitMQ process.     To remediate this issue, customers should upgrade to version 0.2.1 of rabbitmq-aw…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-489</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9133">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-23473 – The SolarWinds Access Rights Manager was found to contain a hard-coded credentia...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23473</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23473</guid>
    <pubDate>Tue, 14 May 2024 14:59:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-23473</strong></p>
  <p>The SolarWinds Access Rights Manager was found to contain a hard-coded credential authentication bypass vulnerability. If exploited, this vulnerability allows access to the RabbitMQ management console.   We thank Trend Micro Zero Day Initiative (ZDI) for its ongoing partnership in coordinating with SolarWinds on responsible disclosure of this and other potential vulnerabilities.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23473">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-1156 – Incorrect directory permissions for the shared NI RabbitMQ service may allow a l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-1156</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-1156</guid>
    <pubDate>Tue, 20 Feb 2024 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-1156</strong></p>
  <p>Incorrect directory permissions for the shared NI RabbitMQ service may allow a local authenticated user to read RabbitMQ configuration information and potentially enable escalation of privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1156">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-40256 – A vulnerability was discovered in Veritas NetBackup Snapshot Manager before 10.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40256</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40256</guid>
    <pubDate>Fri, 11 Aug 2023 05:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-40256</strong></p>
  <p>A vulnerability was discovered in Veritas NetBackup Snapshot Manager before 10.2.0.1 that allowed untrusted clients to interact with the RabbitMQ service. This was caused by improper validation of the client certificate due to misconfiguration of the RabbitMQ service. Exploiting this impacts the confidentiality and integrity of messages controlling the backup and restore jobs, and could result in…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40256">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-26512 – CWE-502 Deserialization of Untrusted Data at the rabbitmq-connector plugin modul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-26512</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-26512</guid>
    <pubDate>Mon, 17 Jul 2023 08:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-26512</strong></p>
  <p>CWE-502 Deserialization of Untrusted Data at the rabbitmq-connector plugin module in Apache EventMesh (incubating) V1.7.0\V1.8.0 on windows\linux\mac os e.g. platforms allows attackers to send controlled message and   remote code execute via rabbitmq messages. Users can use the code under the master branch in project repo to fix this issue, we will release the new version as soon as possible.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26512">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-24567 – Dell NetWorker versions 19.5 and earlier contain 'RabbitMQ' version disclosure v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-24567</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-24567</guid>
    <pubDate>Wed, 01 Mar 2023 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-24567</strong></p>
  <p>Dell NetWorker versions 19.5 and earlier contain 'RabbitMQ' version disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and may launch target-specific attacks.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24567">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-24447 – A cross-site request forgery (CSRF) vulnerability in Jenkins RabbitMQ Consumer P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-24447</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-24447</guid>
    <pubDate>Thu, 26 Jan 2023 21:18:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-24447</strong></p>
  <p>A cross-site request forgery (CSRF) vulnerability in Jenkins RabbitMQ Consumer Plugin 2.8 and earlier allows attackers to connect to an attacker-specified AMQP(S) URL using attacker-specified username and password.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24447">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-43799 – Zulip is an open-source team collaboration tool. Zulip Server installs RabbitMQ ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-43799</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-43799</guid>
    <pubDate>Tue, 25 Jan 2022 21:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-43799</strong></p>
  <p>Zulip is an open-source team collaboration tool. Zulip Server installs RabbitMQ for internal message passing. In versions of Zulip Server prior to 4.9, the initial installation (until first reboot, or restart of RabbitMQ) does not successfully limit the default ports which RabbitMQ opens; this includes port 25672, the RabbitMQ distribution port, which is used as a management port. RabbitMQ's defa…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-338</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-43799">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-0279 – Juniper Networks Contrail Cloud (CC) releases prior to 13.6.0 have RabbitMQ serv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-0279</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-0279</guid>
    <pubDate>Thu, 15 Jul 2021 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-0279</strong></p>
  <p>Juniper Networks Contrail Cloud (CC) releases prior to 13.6.0 have RabbitMQ service enabled by default with hardcoded credentials. The messaging services of RabbitMQ are used when coordinating operations and status information among Contrail services. An attacker with access to an administrative service for RabbitMQ (e.g. GUI), can use these hardcoded credentials to cause a Denial of Service (DoS…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-0279">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22116 – RabbitMQ all versions prior to 3.8.16 are prone to a denial of service vulnerabi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22116</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22116</guid>
    <pubDate>Tue, 08 Jun 2021 12:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22116</strong></p>
  <p>RabbitMQ all versions prior to 3.8.16 are prone to a denial of service vulnerability due to improper input validation in AMQP 1.0 client connection endpoint. A malicious user can exploit the vulnerability by sending malicious AMQP messages to the target RabbitMQ instance having the AMQP 1.0 plugin enabled.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22116">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22117 – RabbitMQ installers on Windows prior to version 3.8.16 do not harden plugin dire...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22117</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22117</guid>
    <pubDate>Tue, 18 May 2021 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22117</strong></p>
  <p>RabbitMQ installers on Windows prior to version 3.8.16 do not harden plugin directory permissions, potentially allowing attackers with sufficient local filesystem permissions to add arbitrary plugins.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22117">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-36282 – JMS Client for RabbitMQ 1.x before 1.15.2 and 2.x before 2.2.0 is vulnerable to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36282</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36282</guid>
    <pubDate>Fri, 12 Mar 2021 01:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-36282</strong></p>
  <p>JMS Client for RabbitMQ 1.x before 1.15.2 and 2.x before 2.2.0 is vulnerable to unsafe deserialization that can result in code execution via crafted StreamMessage data.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36282">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-35196 – The official rabbitmq docker images before 3.7.13-beta.1-management-alpine (Alpi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-35196</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-35196</guid>
    <pubDate>Thu, 17 Dec 2020 02:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-35196</strong></p>
  <p>The official rabbitmq docker images before 3.7.13-beta.1-management-alpine (Alpine specific) contain a blank password for a root user. System using the rabbitmq docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-35196">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-11982 – An issue was found in Apache Airflow versions 1.10.10 and below. When using Cele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-11982</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-11982</guid>
    <pubDate>Fri, 17 Jul 2020 00:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-11982</strong></p>
  <p>An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attack can connect to the broker (Redis, RabbitMQ) directly, it was possible to insert a malicious payload directly to the broker which could lead to a deserialization attack (and thus remote code execution) on the Worker.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11982">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-11981 – An issue was found in Apache Airflow versions 1.10.10 and below. When using Cele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-11981</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-11981</guid>
    <pubDate>Fri, 17 Jul 2020 00:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-11981</strong></p>
  <p>An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attacker can connect to the broker (Redis, RabbitMQ) directly, it is possible to inject commands, resulting in the celery worker running arbitrary commands.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11981">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-11972 – Apache Camel RabbitMQ enables Java deserialization by default. Apache Camel 2.22...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-11972</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-11972</guid>
    <pubDate>Thu, 14 May 2020 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-11972</strong></p>
  <p>Apache Camel RabbitMQ enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11972">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-2032 – A vulnerability exists in the Aruba AirWave Management Platform 8.x prior to 8.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-2032</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-2032</guid>
    <pubDate>Fri, 31 Jan 2020 20:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-2032</strong></p>
  <p>A vulnerability exists in the Aruba AirWave Management Platform 8.x prior to 8.2 in the management interface of an underlying system component called RabbitMQ, which could let a malicious user obtain sensitive information. This interface listens on TCP port 15672 and 55672</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-2032">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-19340 – A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19340</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19340</guid>
    <pubDate>Thu, 19 Dec 2019 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-19340</strong></p>
  <p>A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.3, where enabling RabbitMQ manager by setting it with '-e rabbitmq_enable_manager=true' exposes the RabbitMQ management interface publicly, as expected. If the default admin user is still active, an attacker could guess the password and gain access to the system.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-1188</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19340">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-18609 – An issue was discovered in amqp_handle_input in amqp_connection.c in rabbitmq-c ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-18609</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-18609</guid>
    <pubDate>Sun, 01 Dec 2019 22:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-18609</strong></p>
  <p>An issue was discovered in amqp_handle_input in amqp_connection.c in rabbitmq-c 0.9.0. There is an integer overflow that leads to heap memory corruption in the handling of CONNECTION_STATE_HEADER. A rogue server could return a malicious frame header that leads to a smaller target_size value than needed. This condition is then carried on to a memcpy function that copies too much data into a heap b…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-18609">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-11287 – Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and R...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-11287</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-11287</guid>
    <pubDate>Sat, 23 Nov 2019 00:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-11287</strong></p>
  <p>Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is vulnerable to a denial of service attack. The "X-Reason" HTTP Header can be leveraged to insert a malicious Erlang format string that will expand and consume the heap, resulting in…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-11287">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-9546 – SolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation thr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-9546</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-9546</guid>
    <pubDate>Fri, 01 Mar 2019 22:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-9546</strong></p>
  <p>SolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation through the RabbitMQ service.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-9546">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-16879 – Ansible Tower before version 3.3.3 does not set a secure channel as it is using ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-16879</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-16879</guid>
    <pubDate>Thu, 03 Jan 2019 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-16879</strong></p>
  <p>Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for messaging celery workers from RabbitMQ. This could lead in data leak of sensitive information such as passwords as well as denial of service attacks by deleting projects or inventory files.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-311</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-16879">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1279 – Pivotal RabbitMQ for PCF, all versions, uses a deterministically generated cooki...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1279</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1279</guid>
    <pubDate>Mon, 10 Dec 2018 19:29:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1279</strong></p>
  <p>Pivotal RabbitMQ for PCF, all versions, uses a deterministically generated cookie that is shared between all machines when configured in a multi-tenant cluster. A remote attacker who can gain information about the network topology can guess this cookie and, if they have access to the right ports on any server in the MQ cluster can use this cookie to gain full control over the entire cluster.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-330</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1279">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-4966 – An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4966</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4966</guid>
    <pubDate>Tue, 13 Jun 2017 06:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-4966</strong></p>
  <p>An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to 1.6.18, and 1.7.x versions prior to 1.7.15. RabbitMQ management UI stores signed-in user credentials in a browser's local storage without expiration, making it possible to retrieve th…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4966">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-9877 – An issue was discovered in Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before 3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9877</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9877</guid>
    <pubDate>Thu, 29 Dec 2016 09:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-9877</strong></p>
  <p>An issue was discovered in Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before 3.6.6 and RabbitMQ for PCF 1.5.x before 1.5.20, 1.6.x before 1.6.12, and 1.7.x before 1.7.7. MQTT (MQ Telemetry Transport) connection authentication with a username/password pair succeeds if an existing username is provided but the password is omitted from the connection request. Connections that use TLS with a client-p…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9877">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-0929 – The metrics-collection component in RabbitMQ for Pivotal Cloud Foundry (PCF) 1.6...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-0929</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-0929</guid>
    <pubDate>Sun, 18 Sep 2016 02:59:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-0929</strong></p>
  <p>The metrics-collection component in RabbitMQ for Pivotal Cloud Foundry (PCF) 1.6.x before 1.6.4 logs command lines of failed commands, which might allow context-dependent attackers to obtain sensitive information by reading the log data, as demonstrated by a syslog message that contains credentials from a command line.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-0929">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-5329 – The TripleO Heat templates (tripleo-heat-templates), as used in Red Hat Enterpri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-5329</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-5329</guid>
    <pubDate>Mon, 11 Apr 2016 21:59:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-5329</strong></p>
  <p>The TripleO Heat templates (tripleo-heat-templates), as used in Red Hat Enterprise Linux OpenStack Platform 7.0, do not properly use the configured RabbitMQ credentials, which makes it easier for remote attackers to obtain access to services in deployed overclouds by leveraging knowledge of the default credentials.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-5329">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
