← Back

CVE-2019-11287

nvd nist
Published: Nov 23, 2019Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is vulnerable to a denial of service attack. The "X-Reason" HTTP Header can be leveraged to insert a malicious Erlang format string that will expand and consume the heap, resulting in the server crashing.

Affected (8)

Show all products
1 product
Rabbitmq Server
Rabbitmq
1 product
Fedora
1 product
Openstack
1 product
Debian Linux
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
From 3.8.0 to 3.8.1
Pivotal Software
From 3.7.0 to 3.7.21
From 1.16.0 to 1.16.7
From 1.17.0 to 1.17.4
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 30
Version 31
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 15
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 9.0

References (12)

Source: security@pivotal.io
Third Party Advisory
Source: security@pivotal.io
Third Party Advisory
Source: security@pivotal.io
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.