SUSE has issued an advisory on December 8: https://lists.suse.com/pipermail/sle-security-updates/2022-December/013208.html The issue is fixed upstream in 3.8.32: https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-v9gv-xp36-jgj8 Mageia 8 is also affected.
Status comment: (none) => Fixed upstream in 3.8.32Whiteboard: (none) => MGA8TOO
Equivalent openSUSE advisory: https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/TLCI5JFBQWTZ4GBJ2CEVSH6AKPMTXB7D/
"Nobody" is the maintainer of this package, so assigning to all packagers collectively
Assignee: bugsquad => pkg-bugsCC: (none) => marja11
Mageia 8 EOL.
CC: (none) => nicolas.salgueroSource RPM: rabbitmq-server-3.8.18-1.mga9.src.rpm => rabbitmq-server-3.8.18-1.mga8.src.rpmStatus comment: Fixed upstream in 3.8.32 => (none)Status: NEW => RESOLVEDWhiteboard: MGA8TOO => (none)CVE: (none) => CVE-2022-31008Version: Cauldron => 8Resolution: (none) => OLD