Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2016-9877

issue was discovered in Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before 3.6.6 and RabbitMQ…

Technology

RabbitMQ

CVSS Score

9.8 / 10.0

Affected Versions

3.0.0; 3.0.1; 3.0.2; 3.0.3

Upstream Fix

See upstream advisory

Published

December 29, 2016

OSSeva Coverage

Fixed upstream

Description

An issue was discovered in Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before 3.6.6 and RabbitMQ for PCF 1.5.x before 1.5.20, 1.6.x before 1.6.12, and 1.7.x before 1.7.7. MQTT (MQ Telemetry Transport) connection authentication with a username/password pair succeeds if an existing username is provided but the password is omitted from the connection request. Connections that use TLS with a client-provided certificate are not affected.

Is your RabbitMQ deployment affected?

If you're running 3.0.0; 3.0.1; 3.0.2; 3.0.3, you need this patch. Book a discovery call to get covered.