漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
HTTP API's queue deletion endpoint does not verify that the user has a required permission
Vulnerability Description
RabbitMQ is a feature rich, multi-protocol messaging and streaming broker. In affected versions queue deletion via the HTTP API was not verifying the `configure` permission of the user. Users who had all of the following: 1. Valid credentials, 2. Some permissions for the target virtual host & 3. HTTP API access. could delete queues it had no (deletion) permissions for. This issue has been addressed in version 3.12.11 of the open source rabbitMQ release and in versions 1.5.2, 3.13.0, and 4.0.0 of the tanzu release. Users are advised to upgrade. Users unable to upgrade may disable management plugin and use, for example, Prometheus and Grafana for monitoring.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Vulnerability Type
访问控制不恰当
Vulnerability Title
RabbitMQ 访问控制错误漏洞
Vulnerability Description
RabbitMQ是RabbitMQ开源的一个功能丰富的多协议消息和流媒体代理。 RabbitMQ存在访问控制错误漏洞,该漏洞源于通过HTTP API删除队列时未验证用户的configure权限。具有有效凭证、目标虚拟主机的部分权限以及HTTP API访问权限的用户可以删除其没有删除权限的队列。
CVSS Information
N/A
Vulnerability Type
N/A