VDB

CVE-2021-22117

CVE-2021-22117 PUBLISHED CVSS 7.800000190734863 HIGH

RabbitMQ installers on Windows prior to version 3.8.16 do not harden plugin directory permissions, potentially allowing attackers with sufficient local filesystem permissions to add arbitrary plugins.

EPSS 0.61% · 47.4th percentile

Risk Scores

CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.61%
47.4th percentile

Affected Products

VendorProductVersions
Bitnamirabbitmq3.8.0
Bitnamirabbitmq3.8.0

Timeline

  • CVE Published
  • May 19, 2021 EPSS Score
  • May 26, 2021 EPSS Score
  • Jul 1, 2021 PoC Published
  • Sep 22, 2021 EPSS Score
  • Nov 23, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Jan 23, 2022 EPSS Score
  • Mar 26, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 27, 2022 EPSS Score
  • Jul 29, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›