PT-2019-6377 · Pivotal+1 · Rabbitmq

Published

2019-10-25

·

Updated

2022-07-01

·

CVE-2019-11291

CVSS v2.0

4.9

Medium

VectorAV:N/AC:M/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Pivotal RabbitMQ versions prior to 3.7.20 Pivotal RabbitMQ version 3.8 prior to 3.8.1 RabbitMQ for PCF versions 1.16.x prior to 1.16.7 RabbitMQ for PCF versions 1.17.x prior to 1.17.4
Description The issue is related to the improper sanitization of user input in the federation and shovel endpoints, which could allow a remote authenticated malicious user with administrative access to craft a cross-site scripting attack. This attack could potentially grant access to virtual hosts and policy management information via the vhost or node name fields. The vulnerability may also impact the integrity of data.
Recommendations For Pivotal RabbitMQ versions prior to 3.7.20, update to version 3.7.20 or later. For Pivotal RabbitMQ version 3.8 prior to 3.8.1, update to version 3.8.1 or later. For RabbitMQ for PCF versions 1.16.x prior to 1.16.7, update to version 1.16.7 or later. For RabbitMQ for PCF versions 1.17.x prior to 1.17.4, update to version 1.17.4 or later. As a temporary workaround, consider restricting access to the federation and shovel endpoints until a patch is available.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-04781
CVE-2019-11291
GHSA-9PF7-F47Q-MWPQ
RHSA-2020:0553

Affected Products

Rabbitmq