Updated rabbitmq-server packages fix security vulnerabilities
Publication date: 06 Aug 2021Modification date: 06 Aug 2021
Type: security
Affected Mageia releases : 8
CVE: CVE-2021-22116 , CVE-2021-32718 , CVE-2021-32719
Description
Updated rabbitmq-server packages fix security vulnerabilities: RabbitMQ all versions prior to 3.8.16 are prone to a denial of service vulnerability due to improper input validation in AMQP 1.0 client connection endpoint. A malicious user can exploit the vulnerability by sending malicious AMQP messages to the target RabbitMQ instance having the AMQP 1.0 plugin enabled (CVE-2021-22116). RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.17, a new user being added via management UI could lead to the user's bane being rendered in a confirmation message without proper "