MGASA-2021-0390 - Updated rabbitmq-server packages fix security vulnerabilities

Publication date: 06 Aug 2021
URL: https://advisories.mageia.org/MGASA-2021-0390.html
Type: security
Affected Mageia releases: 8
CVE: CVE-2021-22116,
     CVE-2021-32718,
     CVE-2021-32719

Updated rabbitmq-server packages fix security vulnerabilities:

RabbitMQ all versions prior to 3.8.16 are prone to a denial of service
vulnerability due to improper input validation in AMQP 1.0 client
connection endpoint. A malicious user can exploit the vulnerability by
sending malicious AMQP messages to the target RabbitMQ instance having
the AMQP 1.0 plugin enabled (CVE-2021-22116).

RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior
to version 3.8.17, a new user being added via management UI could lead
to the user's bane being rendered in a confirmation message without proper
"