CVE-2018-1279 Information
Feb 14, 2021
cve
Description
Pivotal RabbitMQ for PCF all versions uses a deterministically generated cookie that is shared between all machines when configured in a multi-tenant cluster. A remote attacker who can gain information about the network topology can guess this cookie and if they have access to the right ports on any server in the MQ cluster can use this cookie to gain full control over the entire cluster.
CVSS Vector
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Reference
https://pivotal.io/security/cve-2018-1279
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
6.5
Share on: