The Management plugin in RabbitMQ before 3.6.1 allows remote authenticated users with certain privileges to cause a denial of service (resource consumption) via the (1) lengthsage or (2) lengthsincr parameter.
{ "binaries": [ { "binary_version": "3.5.7-1ubuntu0.16.04.4+esm2", "binary_name": "rabbitmq-server" } ] }