RabbitMQ 'rabbit_mgmt_util.erl' Security Bypass Vulnerability
BID:71859
Info
RabbitMQ 'rabbit_mgmt_util.erl' Security Bypass Vulnerability
| Bugtraq ID: | 71859 |
| Class: | Access Validation Error |
| CVE: |
CVE-2014-9494 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 16 2014 12:00AM |
| Updated: | Dec 16 2014 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
RabbitMQ RabbitMQ 3.3 |
| Not Vulnerable: |
RabbitMQ RabbitMQ 3.4 |
Discussion
RabbitMQ 'rabbit_mgmt_util.erl' Security Bypass Vulnerability
RabbitMQ is prone to a security-bypass vulnerability.
An attacker can exploit this issue to bypass certain security restrictions to perform unauthorized actions. This may aid in further attacks.
RabbitMQ 3.3.0 is vulnerable. Other versions may also be affected.
RabbitMQ is prone to a security-bypass vulnerability.
An attacker can exploit this issue to bypass certain security restrictions to perform unauthorized actions. This may aid in further attacks.
RabbitMQ 3.3.0 is vulnerable. Other versions may also be affected.
Exploit / POC
RabbitMQ 'rabbit_mgmt_util.erl' Security Bypass Vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
RabbitMQ 'rabbit_mgmt_util.erl' Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
RabbitMQ 'rabbit_mgmt_util.erl' Security Bypass Vulnerability
References:
References:
- [Security] 3.3.x rabbitmq_management incorrectly trusts "X-Forwarded-For" header (Simon MacMullen)
- Build on old Erlang bug26414 (RabbitMQ)
- Don't use wrq:peer/1 bug26414 (RabbitMQ)
- RabbitMQ Homepage (RabbitMQ)
- Release: RabbitMQ 3.4.0 (RabbitMQ)
- Bug 1174872 - rabbitmq-server: insufficient 'X-Forwarded-For' header validation (Red Hat)