{"schema_version":"1.7.3","id":"GHSA-hrfh-7j5f-8ccr","published":"2022-05-24T17:01:50Z","modified":"2025-12-10T00:40:03.353521Z","aliases":["CVE-2019-11287"],"summary":"Pivotal RabbitMQ is vulnerable to a denial of service attack","details":"Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is vulnerable to a denial of service attack. The \"X-Reason\" HTTP Header can be leveraged to insert a malicious Erlang format string that will expand and consume the heap, resulting in the server crashing.","affected":[{"package":{"name":"RabbitMQ","ecosystem":"Hex","purl":"pkg:hex/RabbitMQ"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.7.0"},{"fixed":"3.7.21"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-hrfh-7j5f-8ccr/GHSA-hrfh-7j5f-8ccr.json"}},{"package":{"name":"RabbitMQ","ecosystem":"Hex","purl":"pkg:hex/RabbitMQ"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.8.0"},{"fixed":"3.8.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-hrfh-7j5f-8ccr/GHSA-hrfh-7j5f-8ccr.json"}},{"package":{"name":"RabbitMQ","ecosystem":"Hex","purl":"pkg:hex/RabbitMQ"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.16.7"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-hrfh-7j5f-8ccr/GHSA-hrfh-7j5f-8ccr.json"}},{"package":{"name":"RabbitMQ","ecosystem":"Hex","purl":"pkg:hex/RabbitMQ"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.17.0"},{"fixed":"1.17.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-hrfh-7j5f-8ccr/GHSA-hrfh-7j5f-8ccr.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-11287"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2020:0078"},{"type":"WEB","url":"https://github.com/DrunkenShells/Disclosures/tree/master/CVE-2019-11287-DoS%20via%20Heap%20Overflow-RabbitMQ%20Web%20Management%20Plugin"},{"type":"PACKAGE","url":"https://github.com/rabbitmq/rabbitmq-server"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2021/07/msg00011.html"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EEQ6O7PMNJKYFMQYHAB55L423GYK63SO"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PYTGR3D5FW2O25RXZOTIZMOD2HAUVBE4"},{"type":"WEB","url":"https://pivotal.io/security/cve-2019-11287"}],"database_specific":{"cwe_ids":["CWE-134","CWE-400"],"github_reviewed":true,"github_reviewed_at":"2022-07-01T11:48:49Z","nvd_published_at":"2019-11-23T00:15:00Z","severity":"HIGH"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}