PT-2017-4083 · Pivotal+1 · Rabbitmq For Pcf+1

Published

2017-06-13

·

Updated

2025-04-02

·

CVE-2017-4965

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions RabbitMQ versions 3.4.x through 3.5.x and 3.6.x prior to 3.6.9 RabbitMQ for PCF versions 1.5.x and 1.6.x prior to 1.6.18 and 1.7.x prior to 1.7.15
Description The issue is related to insufficient protection measures in the RabbitMQ management UI, which makes several forms vulnerable to XSS attacks. This could allow a remote attacker to impact data integrity.
Recommendations For RabbitMQ versions 3.4.x through 3.5.x and 3.6.x prior to 3.6.9, update to version 3.6.9 or later. For RabbitMQ for PCF versions 1.5.x, update to version 1.6.18 or later. For RabbitMQ for PCF versions 1.6.x prior to 1.6.18, update to version 1.6.18 or later. For RabbitMQ for PCF versions 1.7.x prior to 1.7.15, update to version 1.7.15 or later. As a temporary workaround, consider restricting access to the RabbitMQ management UI to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2021-01440
BDU:2021-01441
CVE-2017-4965
DLA-2710-1
DLA-2710-2
SUSE-RU-2020:2072-1

Affected Products

Rabbitmq
Rabbitmq For Pcf