CVE-2023-46118
Denial of Service by publishing large messages over the HTTP API
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
RabbitMQ is a multi-protocol messaging and streaming broker. HTTP API did not enforce an HTTP request body limit, making it vulnerable for denial of service (DoS) attacks with very large messages. An authenticated user with sufficient credentials can publish a very large messages over the HTTP API and cause target node to be terminated by an "out-of-memory killer"-like mechanism. This vulnerability has been patched in versions 3.11.24 and 3.12.7.
RabbitMQ es un corredor de transmisión y mensajería multiprotocolo. La API HTTP no aplicaba un límite de cuerpo de solicitud HTTP, lo que la hacía vulnerable a ataques de denegación de servicio (DoS) con mensajes muy grandes. Un usuario autenticado con credenciales suficientes puede publicar mensajes muy grandes a través de la API HTTP y hacer que el nodo de destino finalice mediante un mecanismo similar al "eliminador de memoria insuficiente". Esta vulnerabilidad ha sido parcheada en las versiones 3.11.24 y 3.12.7.
A flaw was found in the rabbitmq-server. An authenticated user with sufficient credentials can publish very large messages over the HTTP API and cause the target node to be terminated by an "out-of-memory killer" like mechanism.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-10-16 CVE Reserved
- 2023-10-24 CVE Published
- 2024-08-02 CVE Updated
- 2024-10-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-400: Uncontrolled Resource Consumption
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
https://lists.debian.org/debian-lts-announce/2023/12/msg00009.html | ||
https://www.debian.org/security/2023/dsa-5571 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-w6cq-9cf4-gqpg | 2023-12-14 | |
https://access.redhat.com/security/cve/CVE-2023-46118 | 2024-01-16 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2246512 | 2024-01-16 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Vmware Search vendor "Vmware" | Rabbitmq Search vendor "Vmware" for product "Rabbitmq" | < 3.11.24 Search vendor "Vmware" for product "Rabbitmq" and version " < 3.11.24" | - |
Affected
| ||||||
Vmware Search vendor "Vmware" | Rabbitmq Search vendor "Vmware" for product "Rabbitmq" | >= 3.12.0 < 3.12.7 Search vendor "Vmware" for product "Rabbitmq" and version " >= 3.12.0 < 3.12.7" | - |
Affected
|