Back

MEDIUM

RabbitMQ XSS attack via federation and shovel endpoints

Published Nov 22, 2019

Description

Pivotal RabbitMQ, 3.7 versions prior to v3.7.20 and 3.8 version prior to v3.8.1, and RabbitMQ for PCF, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain two endpoints, federation and shovel, which do not properly sanitize user input. A remote authenticated malicious user with administrative access could craft a cross site scripting attack via the vhost or node name fields that could grant access to virtual hosts and policy management information.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner pivotal
Published Nov 22, 2019
Updated Sep 17, 2024
Reserved Apr 18, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Dec 13, 2019
GHSA-9PF7-F47Q-MWPQ