RabbitMQ 是一种消息和流式传输代理。在版本 3.13.15、4.0.20、4.1.11、4.2.6 和 4.3.1 之前,Shovel 管理资源中的 函数委托给了 ,该函数接受监控标签(monitoring tag)。然而, 包含了 DELETE 方法,而 函数在删除或重启 Shovel 运行时参数时,未进行额外的角色检查。因此,一个仅应具有只读可见性的监控用户(monitoring user),可以删除或重启其在任意可见 vhost 中的任何 Shovel。这种只读的监控用户能够删除或重启任意动态 Sho
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| rabbitmq | rabbitmq-server | >= 3.13.0, < 3.13.15 |
affected |
>= 4.0.0, < 4.0.20 |
affected | ||
>= 4.1.0, < 4.1.11 |
affected | ||
>= 4.2.0, < 4.2.6 |
affected | ||
>= 4.3.0, < 4.3.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| rabbitmq | rabbitmq-server | >= 3.13.0, < 3.13.15 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet