7.8

CVE-2017-4966

An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to 1.6.18, and 1.7.x versions prior to 1.7.15. RabbitMQ management UI stores signed-in user credentials in a browser's local storage without expiration, making it possible to retrieve them using a chained attack.

Data is provided by the National Vulnerability Database (NVD)
BroadcomRabbitmq Server Version3.4.0
BroadcomRabbitmq Server Version3.4.1
BroadcomRabbitmq Server Version3.4.2
BroadcomRabbitmq Server Version3.4.3
BroadcomRabbitmq Server Version3.4.4
BroadcomRabbitmq Server Version3.5.0
BroadcomRabbitmq Server Version3.5.1
BroadcomRabbitmq Server Version3.5.2
BroadcomRabbitmq Server Version3.5.3
BroadcomRabbitmq Server Version3.5.6
BroadcomRabbitmq Server Version3.6.7
Pivotal SoftwareRabbitmq Version3.5.4
Pivotal SoftwareRabbitmq Version3.5.5
Pivotal SoftwareRabbitmq Version3.5.7
Pivotal SoftwareRabbitmq Version3.6.0
Pivotal SoftwareRabbitmq Version3.6.1
Pivotal SoftwareRabbitmq Version3.6.2
Pivotal SoftwareRabbitmq Version3.6.3
Pivotal SoftwareRabbitmq Version3.6.4
Pivotal SoftwareRabbitmq Version3.6.5
Pivotal SoftwareRabbitmq Version3.6.6
Pivotal SoftwareRabbitmq Version1.5.0 SwPlatformpivotal_cloud_foundry
Pivotal SoftwareRabbitmq Version1.5.1 SwPlatformpivotal_cloud_foundry
Pivotal SoftwareRabbitmq Version1.5.2 SwPlatformpivotal_cloud_foundry
Pivotal SoftwareRabbitmq Version1.5.3 SwPlatformpivotal_cloud_foundry
Pivotal SoftwareRabbitmq Version1.5.4 SwPlatformpivotal_cloud_foundry
Pivotal SoftwareRabbitmq Version1.5.5 SwPlatformpivotal_cloud_foundry
Pivotal SoftwareRabbitmq Version1.5.6 SwPlatformpivotal_cloud_foundry
Pivotal SoftwareRabbitmq Version1.5.7 SwPlatformpivotal_cloud_foundry
Pivotal SoftwareRabbitmq Version1.5.8 SwPlatformpivotal_cloud_foundry
Pivotal SoftwareRabbitmq Version1.5.9 SwPlatformpivotal_cloud_foundry
Pivotal SoftwareRabbitmq Version1.5.10 SwPlatformpivotal_cloud_foundry
Pivotal SoftwareRabbitmq Version1.5.11 SwPlatformpivotal_cloud_foundry
Pivotal SoftwareRabbitmq Version1.5.12 SwPlatformpivotal_cloud_foundry
Pivotal SoftwareRabbitmq Version1.5.13 SwPlatformpivotal_cloud_foundry
Pivotal SoftwareRabbitmq Version1.5.14 SwPlatformpivotal_cloud_foundry
Pivotal SoftwareRabbitmq Version1.5.15 SwPlatformpivotal_cloud_foundry
Pivotal SoftwareRabbitmq Version1.5.17 SwPlatformpivotal_cloud_foundry
Pivotal SoftwareRabbitmq Version1.5.18 SwPlatformpivotal_cloud_foundry
Pivotal SoftwareRabbitmq Version1.5.19 SwPlatformpivotal_cloud_foundry
Pivotal SoftwareRabbitmq Version1.6.0 SwPlatformpivotal_cloud_foundry
Pivotal SoftwareRabbitmq Version1.6.1 SwPlatformpivotal_cloud_foundry
Pivotal SoftwareRabbitmq Version1.6.2 SwPlatformpivotal_cloud_foundry
Pivotal SoftwareRabbitmq Version1.6.3 SwPlatformpivotal_cloud_foundry
Pivotal SoftwareRabbitmq Version1.6.4 SwPlatformpivotal_cloud_foundry
Pivotal SoftwareRabbitmq Version1.6.5 SwPlatformpivotal_cloud_foundry
Pivotal SoftwareRabbitmq Version1.6.6 SwPlatformpivotal_cloud_foundry
Pivotal SoftwareRabbitmq Version1.6.7 SwPlatformpivotal_cloud_foundry
Pivotal SoftwareRabbitmq Version1.6.8 SwPlatformpivotal_cloud_foundry
Pivotal SoftwareRabbitmq Version1.6.9 SwPlatformpivotal_cloud_foundry
Pivotal SoftwareRabbitmq Version1.6.10 SwPlatformpivotal_cloud_foundry
Pivotal SoftwareRabbitmq Version1.6.12 SwPlatformpivotal_cloud_foundry
Pivotal SoftwareRabbitmq Version1.6.13 SwPlatformpivotal_cloud_foundry
Pivotal SoftwareRabbitmq Version1.6.14 SwPlatformpivotal_cloud_foundry
Pivotal SoftwareRabbitmq Version1.6.15 SwPlatformpivotal_cloud_foundry
Pivotal SoftwareRabbitmq Version1.6.16 SwPlatformpivotal_cloud_foundry
Pivotal SoftwareRabbitmq Version1.7.0 SwPlatformpivotal_cloud_foundry
Pivotal SoftwareRabbitmq Version1.7.2 SwPlatformpivotal_cloud_foundry
Pivotal SoftwareRabbitmq Version1.7.3 SwPlatformpivotal_cloud_foundry
Pivotal SoftwareRabbitmq Version1.7.4 SwPlatformpivotal_cloud_foundry
Pivotal SoftwareRabbitmq Version1.7.5 SwPlatformpivotal_cloud_foundry
Pivotal SoftwareRabbitmq Version1.7.6 SwPlatformpivotal_cloud_foundry
Pivotal SoftwareRabbitmq Version1.7.7 SwPlatformpivotal_cloud_foundry
Pivotal SoftwareRabbitmq Version1.7.8 SwPlatformpivotal_cloud_foundry
Pivotal SoftwareRabbitmq Version1.7.9 SwPlatformpivotal_cloud_foundry
Pivotal SoftwareRabbitmq Version1.7.10 SwPlatformpivotal_cloud_foundry
Pivotal SoftwareRabbitmq Version1.7.13 SwPlatformpivotal_cloud_foundry
Pivotal SoftwareRabbitmq Version1.7.14 SwPlatformpivotal_cloud_foundry
DebianDebian Linux Version9.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.09% 0.262
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.