PT-2015-4326 · Pivotal+1 · Rabbitmq

CVE-2014-9650

·

Publicado

2015-01-27

·

Atualizado

2025-04-02

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions RabbitMQ versions 2.1.0 through 3.4.x
Description A CRLF injection issue exists in the management plugin, allowing remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the download parameter to the "api/definitions" endpoint.
Recommendations For RabbitMQ versions 2.1.0 through 3.4.x, update to version 3.4.1 or later to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2014-9650
MGASA-2015-0240
RHSA-2016:0308
RHSA-2016:0367
RHSA-2016:0368
RHSA-2016:0369

Produtos afetados

Rabbitmq