CVE-2021-22117

HIGH

Broadcom Rabbitmq Server < 3.8.16 - Code Injection

Title source: rule
STIX 2.1

Description

RabbitMQ installers on Windows prior to version 3.8.16 do not harden plugin directory permissions, potentially allowing attackers with sufficient local filesystem permissions to add arbitrary plugins.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_misc
https://tanzu.vmware.com/security/cve-2021-22117

Scores

CVSS v3 7.8
EPSS 0.0010
EPSS Percentile 27.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-94 CWE-732
Status published
Products (1)
broadcom/rabbitmq_server 3.8.0 - 3.8.16
Published May 18, 2021
Tracked Since Feb 18, 2026