PT-2019-6097 · Pivotal+2 · Rabbitmq+1
Published
2019-10-15
·
Updated
2023-02-15
·
CVE-2019-11281
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Pivotal RabbitMQ versions prior to 3.7.18
RabbitMQ for PCF versions 1.15.x prior to 1.15.13
RabbitMQ for PCF versions 1.16.x prior to 1.16.6
RabbitMQ for PCF versions 1.17.x prior to 1.17.3
Description
The issue is related to incorrect user input validation in the RabbitMQ message broker. This could allow a remote attacker to impact data integrity. Specifically, the virtual host limits page and the federation management UI do not properly sanitize user input, which could enable a remote authenticated malicious user with administrative access to craft a cross-site scripting attack. This attack could gain access to virtual hosts and policy management information.
Recommendations
For Pivotal RabbitMQ versions prior to 3.7.18, update to version 3.7.18 or later.
For RabbitMQ for PCF versions 1.15.x prior to 1.15.13, update to version 1.15.13 or later.
For RabbitMQ for PCF versions 1.16.x prior to 1.16.6, update to version 1.16.6 or later.
For RabbitMQ for PCF versions 1.17.x prior to 1.17.3, update to version 1.17.3 or later.
As a temporary workaround, consider restricting access to the virtual host limits page and the federation management UI to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Rabbitmq