Back to Vulnerability Directory
MEDIUMFixed upstream
CVE-2024-51988
RabbitMQ HTTP API queue deletion does not check the configure permission
Technology
RabbitMQ
CVSS Score
6.5 / 10.0
Affected Versions
3.12.8 to 3.12.10
Upstream Fix
3.12.11
Published
November 6, 2024
OSSeva Coverage
Fixed upstream
Description
Queue deletion through the HTTP API did not verify the user's configure permission. A user with valid credentials, some permissions on the virtual host and HTTP API access could delete queues they had no permission to delete. Fixed in 3.12.11; disabling the management plugin avoids it. NVD has not scored the record; the score is GitHub's as the CNA.
Is your RabbitMQ deployment affected?
If you're running 3.12.8 to 3.12.10, you need this patch. Book a discovery call to get covered.