CVE-2019-11287: RabbitMQ Web Management Plugin DoS via heap overflow
Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is vulnerable to a denial of service attack. The "X-Reason" HTTP Header can be leveraged to insert a malicious Erlang format string that will expand and consume the heap, resulting in the server crashing.
Other sources
There's a vulnerability in the web management plugin that is vulnerable to a denial of service attack. The "X-Reason" HTTP Header can be leveraged to insert a malicious Erlang format string that will expand and consume the heap, resulting in the server crashing.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-11287?
CVE-2019-11287 is a vulnerability in Pivotal RabbitMQ and RabbitMQ for Pivotal Platform that allows for a denial of service attack.
Which versions of Pivotal RabbitMQ are affected by CVE-2019-11287?
Pivotal RabbitMQ versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1 are affected by CVE-2019-11287.
Which versions of RabbitMQ for Pivotal Platform are affected by CVE-2019-11287?
RabbitMQ for Pivotal Platform 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4 are affected by CVE-2019-11287.
What is the severity of CVE-2019-11287?
CVE-2019-11287 has a severity rating of high.
How do I fix CVE-2019-11287?
To fix CVE-2019-11287, update Pivotal RabbitMQ to version 3.7.21 or later, and update RabbitMQ for Pivotal Platform to version 1.16.7 or later.