VDB
CVE-2021-22117
CVE-2021-22117
PUBLISHED
CVSS 7.800000190734863 HIGH
RabbitMQ installers on Windows prior to version 3.8.16 do not harden plugin directory permissions, potentially allowing attackers with sufficient local filesystem permissions to add arbitrary plugins.
EPSS 0.61% · 47.4th percentile
Risk Scores
CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.61%
47.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | rabbitmq | 3.8.0 |
| Bitnami | rabbitmq | 3.8.0 |
Timeline
- CVE Published
- May 19, 2021 EPSS Score
- May 26, 2021 EPSS Score
- Jul 1, 2021 PoC Published
- Sep 22, 2021 EPSS Score
- Nov 23, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Jan 23, 2022 EPSS Score
- Mar 26, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 27, 2022 EPSS Score
- Jul 29, 2022 EPSS Score