Description
Pivotal RabbitMQ, versions prior to v3.7.18, and RabbitMQ for PCF, versions 1.15.x prior to 1.15.13, versions 1.16.x prior to 1.16.6, and versions 1.17.x prior to 1.17.3, contain two components, the virtual host limits page, and the federation management UI, which do not properly sanitize user input. A remote authenticated malicious user with administrative access could craft a cross site scripting attack that would gain access to virtual hosts and policy management information.
Published: 2019-10-16
Score: 4.8 Medium
EPSS: 1.0% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-2710-1 rabbitmq-server security update
EUVD EUVD EUVD-2019-2969 Pivotal RabbitMQ, versions prior to v3.7.18, and RabbitMQ for PCF, versions 1.15.x prior to 1.15.13, versions 1.16.x prior to 1.16.6, and versions 1.17.x prior to 1.17.3, contain two components, the virtual host limits page, and the federation management UI, which do not properly sanitize user input. A remote authenticated malicious user with administrative access could craft a cross site scripting attack that would gain access to virtual hosts and policy management information.
History

No history.

Subscriptions

Debian Debian Linux
Fedoraproject Fedora
Pivotal Software Rabbitmq
Redhat Openstack Openstack For Ibm Power
cve-icon MITRE

Status: PUBLISHED

Assigner: pivotal

Published:

Updated: 2024-09-16T19:05:38.917Z

Reserved: 2019-04-18T00:00:00.000Z

Link: CVE-2019-11281

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-10-16T16:15:10.340

Modified: 2024-11-21T04:20:50.700

Link: CVE-2019-11281

cve-icon Redhat

Severity : Moderate

Publid Date: 2019-10-14T00:00:00Z

Links: CVE-2019-11281 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses