CVE-2019-11281
RabbitMQ XSS attack
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Pivotal RabbitMQ, versions prior to v3.7.18, and RabbitMQ for PCF, versions 1.15.x prior to 1.15.13, versions 1.16.x prior to 1.16.6, and versions 1.17.x prior to 1.17.3, contain two components, the virtual host limits page, and the federation management UI, which do not properly sanitize user input. A remote authenticated malicious user with administrative access could craft a cross site scripting attack that would gain access to virtual hosts and policy management information.
Pivotal RabbitMQ, versiones anteriores a v3.7.18 y RabbitMQ for PCF, versiones 1.15.x anteriores a 1.15.13, versiones 1.16.x anteriores a 1.16.6 y versiones 1.17.x anteriores a 1.17.3, contienen dos componentes, la página de límites de host virtual y la UI de administración federation que no sanean apropiadamente la entrada del usuario. Un usuario malicioso autenticado remoto con acceso administrativo podría crear un ataque de tipo cross-site scripting que obtendría acceso a hosts virtuales e información de gestión de políticas.
A vulnerability was found in the rabbitmq-server. User input for the virtual host limits page and the federation management UI was not properly sanitized. A remote, authenticated administrative user could create a cross-site scripting attack leading to access to virtual hosts and policy management information.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-04-18 CVE Reserved
- 2019-10-16 CVE Published
- 2024-09-16 CVE Updated
- 2024-10-09 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
https://lists.debian.org/debian-lts-announce/2021/07/msg00011.html | Mailing List |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | < 3.7.18 Search vendor "Pivotal Software" for product "Rabbitmq" and version " < 3.7.18" | - |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | >= 1.15.0 < 1.15.13 Search vendor "Pivotal Software" for product "Rabbitmq" and version " >= 1.15.0 < 1.15.13" | pivotal_cloud_foundry |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | >= 1.16.0 < 1.16.6 Search vendor "Pivotal Software" for product "Rabbitmq" and version " >= 1.16.0 < 1.16.6" | pivotal_cloud_foundry |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Rabbitmq Search vendor "Pivotal Software" for product "Rabbitmq" | >= 1.17.0 < 1.17.3 Search vendor "Pivotal Software" for product "Rabbitmq" and version " >= 1.17.0 < 1.17.3" | pivotal_cloud_foundry |
Affected
| ||||||
Redhat Search vendor "Redhat" | Openstack Search vendor "Redhat" for product "Openstack" | 15 Search vendor "Redhat" for product "Openstack" and version "15" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Openstack For Ibm Power Search vendor "Redhat" for product "Openstack For Ibm Power" | 15 Search vendor "Redhat" for product "Openstack For Ibm Power" and version "15" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 9.0 Search vendor "Debian" for product "Debian Linux" and version "9.0" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 30 Search vendor "Fedoraproject" for product "Fedora" and version "30" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 31 Search vendor "Fedoraproject" for product "Fedora" and version "31" | - |
Affected
|