summaryrefslogtreecommitdiff
path: root/toolchain
diff options
context:
space:
mode:
authorPeter Korsgaard <peter@korsgaard.com>2017-01-13 13:41:18 +0100
committerPeter Korsgaard <peter@korsgaard.com>2017-01-16 11:53:47 +0100
commita502f9acfd7ec5592d1e059e0180928b15abd59f (patch)
treeb67bcc8a0a18982b4472f83e72e1fabfeda9977e /toolchain
parent91888b306bf079a4bb81fb0515b5a7214214ae92 (diff)
rabbitmq-server: security bump to version 3.6.6
Fixes a critical authentication vulnerability in the MQTT plugin (CVE-2016-9877): MQTT (MQ Telemetry Transport) connection authentication with a username/password pair succeeds if an existing username is provided but the password is omitted from the connection request. Connections that use TLS with a client-provided certificate are not affected. Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Diffstat (limited to 'toolchain')
0 files changed, 0 insertions, 0 deletions