Cross-site Scripting in RabbitMQ
Low severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Package
Affected versions
>= 3.7.0, < 3.7.20
>= 3.8.0, < 3.8.1
Patched versions
3.7.20
3.8.1
Description
Published by the National Vulnerability Database
Nov 22, 2019
Published to the GitHub Advisory Database
May 24, 2022
Reviewed
Jul 5, 2022
Last updated
Jan 27, 2023
Pivotal RabbitMQ, 3.7 versions prior to v3.7.20 and 3.8 version prior to v3.8.1, and RabbitMQ for PCF, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain two endpoints, federation and shovel, which do not properly sanitize user input. A remote authenticated malicious user with administrative access could craft a cross site scripting attack via the vhost or node name fields that could grant access to virtual hosts and policy management information.
References