First published: Fri Dec 09 2016(Updated: )
The Management plugin in RabbitMQ before 3.6.1 allows remote authenticated users with certain privileges to cause a denial of service (resource consumption) via the (1) lengths_age or (2) lengths_incr parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Solaris SPARC | =11.3 | |
RabbitMQ (Pivotal Software) | =3.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8786 has a medium severity rating due to its potential for denial of service.
CVE-2015-8786 enables authenticated users to exhaust resources and potentially cause service interruptions.
CVE-2015-8786 affects RabbitMQ versions prior to 3.6.1.
To fix CVE-2015-8786, upgrade RabbitMQ to version 3.6.1 or later.
While upgrading is the best solution for CVE-2015-8786, limiting user privileges may help mitigate the risk.