From fd0c336fd3e7e1b5d61844cff1f9b23af9c8ca4f Mon Sep 17 00:00:00 2001 From: Salvatore Bonaccorso Date: Sun, 2 Jan 2022 14:27:30 +0100 Subject: Update information for CVE-2021-22116/rabbitmq-server --- data/CVE/2021.list | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/data/CVE/2021.list b/data/CVE/2021.list index 1a8deb8ec7..70313beb77 100644 --- a/data/CVE/2021.list +++ b/data/CVE/2021.list @@ -57470,11 +57470,13 @@ CVE-2021-22117 (RabbitMQ installers on Windows prior to version 3.8.16 do not ha - rabbitmq-server (Windows-specific) CVE-2021-22116 (RabbitMQ all versions prior to 3.8.16 are prone to a denial of service ...) {DLA-2710-1} - - rabbitmq-server (bug #989056) + - rabbitmq-server 3.9.4-1 (bug #989056) [bullseye] - rabbitmq-server (Minor issue) [buster] - rabbitmq-server (Minor issue) NOTE: https://tanzu.vmware.com/security/cve-2021-22116 NOTE: https://github.com/rabbitmq/rabbitmq-server/pull/2953 + NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-server/commit/f37a31de55229e6c763215500e376fa16803390b (v3.9.0-beta.1) + NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-server/commit/626d5219115d087a2695c0eb243c7ddb7e154563 (v3.8.15-rc.2) CVE-2021-22115 (Cloud Controller API versions prior to 1.106.0 logs service broker cre ...) NOT-FOR-US: Cloud Controller API CVE-2021-22114 (Addresses partial fix in CVE-2018-1263. Spring-integration-zip, versio ...) -- cgit v1.2.3