Candidate: CVE-2017-4966 PublicDate: 2017-06-13 06:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-4966 https://github.com/rabbitmq/rabbitmq-server/releases/tag/rabbitmq_v3_6_9 Description: An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to 1.6.18, and 1.7.x versions prior to 1.7.15. RabbitMQ management UI stores signed-in user credentials in a browser's local storage without expiration, making it possible to retrieve them using a chained attack. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H [7.8 HIGH] Patches_rabbitmq-server: upstream: https://github.com/rabbitmq/rabbitmq-management/commit/2371633f99ad0d293899384f078872ff9e9f3e10 upstream_rabbitmq-server: released (3.6.9) precise_rabbitmq-server: not-affected precise/esm_rabbitmq-server: DNE (precise was not-affected) trusty_rabbitmq-server: not-affected trusty/esm_rabbitmq-server: DNE (trusty was not-affected) vivid/stable-phone-overlay_rabbitmq-server: DNE vivid/ubuntu-core_rabbitmq-server: DNE xenial_rabbitmq-server: ignored (end of standard support, was needed) esm-infra/xenial_rabbitmq-server: needed yakkety_rabbitmq-server: ignored (reached end-of-life) zesty_rabbitmq-server: ignored (reached end-of-life) artful_rabbitmq-server: not-affected (3.6.10-1) bionic_rabbitmq-server: not-affected (3.6.10-1) cosmic_rabbitmq-server: not-affected (3.6.10-1) disco_rabbitmq-server: not-affected (3.6.10-1) eoan_rabbitmq-server: not-affected (3.6.10-1) focal_rabbitmq-server: not-affected (3.6.10-1) groovy_rabbitmq-server: not-affected (3.6.10-1) hirsute_rabbitmq-server: not-affected (3.6.10-1) impish_rabbitmq-server: not-affected (3.6.10-1) jammy_rabbitmq-server: not-affected (3.6.10-1) devel_rabbitmq-server: not-affected (3.6.10-1)