Added |
CVSS V3.1 |
|
NIST AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N
|
Added |
CVSS V2 |
|
NIST (AV:N/AC:M/Au:S/C:N/I:P/A:N)
|
Added |
CWE |
|
NIST CWE-79
|
Added |
CPE Configuration |
|
OR
*cpe:2.3:a:pivotal_software:rabbitmq:*:*:*:*:*:pivotal_cloud_foundry:*:* versions from (including) 1.16.0 up to (excluding) 1.16.7
*cpe:2.3:a:pivotal_software:rabbitmq:*:*:*:*:*:pivotal_cloud_foundry:*:* versions from (including) 1.17.0 up to (excluding) 1.17.4
*cpe:2.3:a:pivotal_software:rabbitmq:*:*:*:*:*:*:*:* versions from (including) 3.7.0 up to (excluding) 3.7.20
*cpe:2.3:a:pivotal_software:rabbitmq:*:*:*:*:*:*:*:* versions from (including) 3.8.0 up to (excluding) 3.8.1
|
Changed |
Reference Type |
https://pivotal.io/security/cve-2019-11291 No Types Assigned
|
https://pivotal.io/security/cve-2019-11291 Vendor Advisory
|
Added |
CVSS V2 Metadata |
|
Victim must voluntarily interact with attack mechanism
|
Added |
Evaluator Description |
|
A remote authenticated malicious user with administrative access
|