PT-2015-4326 · Pivotal+1 · Rabbitmq

Published

2015-01-27

·

Updated

2025-04-02

·

CVE-2014-9650

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions RabbitMQ versions 2.1.0 through 3.4.x
Description A CRLF injection issue exists in the management plugin, allowing remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the download parameter to the "api/definitions" endpoint.
Recommendations For RabbitMQ versions 2.1.0 through 3.4.x, update to version 3.4.1 or later to resolve the issue.

Fix

Related Identifiers

CVE-2014-9650
MGASA-2015-0240
RHSA-2016:0308
RHSA-2016:0367
RHSA-2016:0368
RHSA-2016:0369

Affected Products

Rabbitmq