Loading
Generated remediation guidance and an executive summary. No account required.
Pivotal RabbitMQ for PCF, all versions, uses a deterministically generated cookie that is shared between all machines when configured in a multi-tenant cluster. A remote attacker who can gain information about the network topology can guess this cookie and, if they have access to the right ports on any server in the MQ cluster can use this cookie to gain full control over the entire cluster.
Use CWE-330, Pivotal Software vendor hub and Rabbitmq product page to widen CVE-2018-1279 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2016-9877, CVE-2017-4966 and CVE-2019-11287 for nearby disclosures in the same product family.