CVE-2017-4966 Information
Feb 14, 2021
cve
Description
An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions all 3.5.x versions and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions 1.6.x versions prior to 1.6.18 and 1.7.x versions prior to 1.7.15. RabbitMQ management UI stores signed-in user credentials in a browser’s local storage without expiration making it possible to retrieve them using a chained attack.
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
https://pivotal.io/security/cve-2017-4966
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.8
Share on: