ZeroHour

CVE-2021-22117

CVSS 3.1
7.8 high
EPSS
<1%p47
Published
()
Modified
Description

RabbitMQ installers on Windows prior to version 3.8.16 do not harden plugin directory permissions, potentially allowing attackers with sufficient local filesystem permissions to add arbitrary plugins.

Vendors
broadcom
Products
rabbitmq server
Weakness
CWE-94, CWE-732
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.