Skip to content

Denial of Service by publishing large messages over the HTTP API

Moderate
michaelklishin published GHSA-w6cq-9cf4-gqpg Oct 23, 2023

Package

erlang RabbitMQ (Erlang)

Affected versions

< 3.12.6

Patched versions

3.12.7, 3.11.24

Description

Summary

Responsibly disclosed by @NSEcho.

HTTP API did not enforce an HTTP request body limit, making it vulnerable for DoS attacks with very large messages.

Details

An authenticated user with sufficient credentials can publish a very large messages over the HTTP API
and cause target node to be terminated by an "out-of-memory killer"-like mechanism.

A PoC was provided to Team RabbitMQ privately.

Impact

Denial of Service

Severity

Moderate
4.9
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
High
User interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

CVE ID

CVE-2023-46118

Weaknesses

Credits