Pivotal.RabbitMQ.X-Reason.HTTP.Header.DoS

description-logoDescription

This indicates an attack attempt to exploit a Denial of Service Vulnerability in Pivotal RabbitMQ for Pivotal Platform.
The vulnerability is due to indefinite memory consumption when processing an X-Reason HTTP header containing a crafted Erlang format string. Successful exploitation will result in the RabbitMQ Erlang program abnormally terminating.

affected-products-logoAffected Products

Pivotal RabbitMQ 3.7 prior to v3.7.21
Pivotal RabbitMQ 3.8 prior to v3.8.1
Pivotal RabbitMQ for Pivotal Platform 1.16 versions prior to 1.16.7
Pivotal RabbitMQ for Pivotal Platform 1.17 versions prior to 1.17.4

Impact logoImpact

Denial of Service: Remote attackers can crash vulnerable systems.

recomended-action-logoRecommended Actions

Apply the most recent upgrade or patch from the vendor.
https://pivotal.io/security/cve-2019-11287

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2020-03-24 15.803 Default_action:pass:drop
2020-02-06 15.773