Oval Definition:oval:org.opensuse.security:def:20181279
Revision Date:2022-05-22Version:1
Title:CVE-2018-1279
Description:

Pivotal RabbitMQ for PCF, all versions, uses a deterministically generated cookie that is shared between all machines when configured in a multi-tenant cluster. A remote attacker who can gain information about the network topology can guess this cookie and, if they have access to the right ports on any server in the MQ cluster can use this cookie to gain full control over the entire cluster.
Family:unixClass:vulnerability
Status:Reference(s):Mitre CVE-2018-1279
SUSE CVE-2018-1279
Platform(s):SUSE OpenStack Cloud 7
SUSE OpenStack Cloud 8
SUSE OpenStack Cloud Crowbar 8
Product(s):
Definition Synopsis
  • Release Information
  • SUSE OpenStack Cloud 8 is installed
  • OR SUSE OpenStack Cloud Crowbar 8 is installed
  • AND Package Information
  • rabbitmq-server is not affected
  • OR rabbitmq-server-plugins is not affected
  • Definition Synopsis
  • SUSE OpenStack Cloud 7 is installed
  • AND rabbitmq-server is not affected
  • BACK