MGASA-2021-0390

Source
https://advisories.mageia.org/MGASA-2021-0390.html
Import Source
https://advisories.mageia.org/MGASA-2021-0390.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2021-0390
Upstream
Published
2021-08-06T09:33:48Z
Modified
2026-04-16T04:42:53Z
Summary
Updated rabbitmq-server packages fix security vulnerabilities
Details

Updated rabbitmq-server packages fix security vulnerabilities:

RabbitMQ all versions prior to 3.8.16 are prone to a denial of service vulnerability due to improper input validation in AMQP 1.0 client connection endpoint. A malicious user can exploit the vulnerability by sending malicious AMQP messages to the target RabbitMQ instance having the AMQP 1.0 plugin enabled (CVE-2021-22116).

RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.17, a new user being added via management UI could lead to the user's bane being rendered in a confirmation message without proper "

References
Credits

Affected packages

Mageia:8 / rabbitmq-server

Package

Name
rabbitmq-server
Purl
pkg:rpm/mageia/rabbitmq-server?arch=source&distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.8.18-1.mga8

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2021-0390.json"