PT-2019-6097 · Pivotal+2 · Rabbitmq+1

Published

2019-10-15

·

Updated

2023-02-15

·

CVE-2019-11281

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Pivotal RabbitMQ versions prior to 3.7.18 RabbitMQ for PCF versions 1.15.x prior to 1.15.13 RabbitMQ for PCF versions 1.16.x prior to 1.16.6 RabbitMQ for PCF versions 1.17.x prior to 1.17.3
Description The issue is related to incorrect user input validation in the RabbitMQ message broker. This could allow a remote attacker to impact data integrity. Specifically, the virtual host limits page and the federation management UI do not properly sanitize user input, which could enable a remote authenticated malicious user with administrative access to craft a cross-site scripting attack. This attack could gain access to virtual hosts and policy management information.
Recommendations For Pivotal RabbitMQ versions prior to 3.7.18, update to version 3.7.18 or later. For RabbitMQ for PCF versions 1.15.x prior to 1.15.13, update to version 1.15.13 or later. For RabbitMQ for PCF versions 1.16.x prior to 1.16.6, update to version 1.16.6 or later. For RabbitMQ for PCF versions 1.17.x prior to 1.17.3, update to version 1.17.3 or later. As a temporary workaround, consider restricting access to the virtual host limits page and the federation management UI to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2021-05298
CVE-2019-11281
DLA-2710-1
DLA-2710-2
RHSA-2020:0078

Affected Products

Astra Linux
Rabbitmq