CVE-2016-9877
issue was discovered in Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before 3.6.6 and RabbitMQ…
Technology
RabbitMQ
CVSS Score
9.8 / 10.0
Affected Versions
3.0.0; 3.0.1; 3.0.2; 3.0.3
Upstream Fix
See upstream advisory
Published
December 29, 2016
OSSeva Coverage
Fixed upstream
Description
An issue was discovered in Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before 3.6.6 and RabbitMQ for PCF 1.5.x before 1.5.20, 1.6.x before 1.6.12, and 1.7.x before 1.7.7. MQTT (MQ Telemetry Transport) connection authentication with a username/password pair succeeds if an existing username is provided but the password is omitted from the connection request. Connections that use TLS with a client-provided certificate are not affected.
Is your RabbitMQ deployment affected?
If you're running 3.0.0; 3.0.1; 3.0.2; 3.0.3, you need this patch. Book a discovery call to get covered.