CyberSectr
Menü
← CVE Veritabanı

CVE-2026-66072

Bilinmiyor

Teknik Veri (Otomatik)

CVSS Skoru
EPSS
CWE
CWE-400
KEV Durumu
Hayır

RabbitMQ, bir mesajlaşma ve akış brokerıdır. 3.13.15, 4.0.20, 4.1.11, 4.2.6 ve 4.3.1 sürümlerinden önceki sürümlerde, get_chunk_selector/1, post-auth abonelik ve resolve_offset_spec çerçevelerinden ham istemci tarafından sağlanan <<"chunk_selector">> özelliğine binary_to_atom çağrısı yapar, beyaz liste veya mevcut koruma olmadan. Herhangi bir akışa okuma erişimi olan kimliği doğrulanmış bir akış istemcisi, broker düğümünü çöktürebilir. Ön koşullar, rabbitmq_stream eklentisinin etkin olması ve kimliği doğrulanmış akış protokolü kullanıcısının en az bir akışa okuma erişimi olmasıdır. Bu sorun, 3.13.15, 4.0.20, 4.1.11, 4.2.6 ve 4.3.1 sürümlerinde giderilmiştir.

Orijinal açıklama (İngilizce)

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.1, get_chunk_selector/1 calls binary_to_atom on the raw client-supplied <<"chunk_selector">> property from post-auth subscribe and resolve_offset_spec frames, with no whitelist and no existing guard. An authenticated stream client with read access to any stream can crash the broker node. Preconditions include rabbitmq_stream plugin enabled Authenticated stream-protocol user with read access to at least one stream. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.1.

Bu CVE için henüz editoryal inceleme yapılmadı. Sadece otomatik teknik veri gösteriliyor.