Index: security/vuxml/vuln.xml =================================================================== --- security/vuxml/vuln.xml (revision 431363) +++ security/vuxml/vuln.xml (working copy) @@ -58,6 +58,38 @@ * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> + + RabbitMQ -- Authentication vulnerability + + + rabbitmq + 3.0.03.5.8 + 3.6.03.6.6 + + + + +

Pivotal.io reports:

+
+

MQTT (MQ Telemetry Transport) connection authentication with a + username/password pair succeeds if an existing username is + provided but the password is omitted from the connection + request. Connections that use TLS with a client-provided + certificate are not affected.

+
+ +
+ + https://pivotal.io/security/cve-2016-9877 + https://github.com/rabbitmq/rabbitmq-server/releases/tag/rabbitmq_v3_6_6 + CVE-2016-9877 + + + 2016-12-06 + 2017-01-13 + +
+ Ansible -- Command execution on Ansible controller from host