// For flags

CVE-2015-0862

 

Severity Score

3.5
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Multiple cross-site scripting (XSS) vulnerabilities in the management web UI in the RabbitMQ management plugin before 3.4.3 allow remote authenticated users to inject arbitrary web script or HTML via (1) message details when a message is unqueued, such as headers or arguments; (2) policy names, which are not properly handled when viewing policies; (3) details for AMQP network clients, such as the version; allow remote authenticated administrators to inject arbitrary web script or HTML via (4) user names, (5) the cluster name; or allow RabbitMQ cluster administrators to (6) modify unspecified content.

Múltiples vulnerabilidades de XSS en la UI web de gestión en el plugin RabbitMQ management anterior a 3.4.3 permiten a usarios remotos autenticados inyectar secuencias de comandos web o HTML arbitrarios a través de (1) los detalles de mensajes cuando un mensaje se saca de la cola, tales como cabeceras o argumentos; (2) los nombres de políticas, los cuales no se manejan correctamente cuando se visualizan las políticas; (3) los detalles para clientes de la red AMQP, tales como la versión; permiten a administradores remotos autenticados inyectar secuencias de comandos web o HTML arbitrarios a través de (4) los nombres de usuarios, (5) el nombre cluster; o permiten a administradores del cluster RabbitMQ (6) modificar contenidos no especificados.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
Single
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2015-01-07 CVE Reserved
  • 2015-01-18 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Pivotal Software
Search vendor "Pivotal Software"
Rabbitmq Management
Search vendor "Pivotal Software" for product "Rabbitmq Management"
<= 3.4.2
Search vendor "Pivotal Software" for product "Rabbitmq Management" and version " <= 3.4.2"
-
Affected