Pivotal RabbitMQ for PCF, all versions, uses a deterministically generated cookie that is shared between all machines when configured in a multi-tenant cluster. A remote attacker who can gain information about the network topology can guess this cookie and, if they have access to the right ports on any server in the MQ cluster can use this cookie to gain full control over the entire cluster.
                
            Metrics
Affected Vendors & Products
References
        History
                    No history.
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: dell
Published: 2018-12-10T19:00:00Z
Updated: 2024-09-17T00:37:15.917Z
Reserved: 2017-12-06T00:00:00
Link: CVE-2018-1279
 Vulnrichment
                        Vulnrichment
                    No data.
 NVD
                        NVD
                    Status : Modified
Published: 2018-12-10T19:29:25.127
Modified: 2024-11-21T03:59:31.903
Link: CVE-2018-1279
 Redhat
                        Redhat