CVE-2021-22117

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
18/05/2021
Last modified:
02/04/2025

Description

RabbitMQ installers on Windows prior to version 3.8.16 do not harden plugin directory permissions, potentially allowing attackers with sufficient local filesystem permissions to add arbitrary plugins.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:broadcom:rabbitmq_server:*:*:*:*:*:*:*:* 3.8.0 (including) 3.8.16 (excluding)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*