PT-2025-12833 · Rabbitmq+6 · Rabbitmq+6

Published

2025-03-25

·

Updated

2026-01-25

·

CVE-2025-30219

CVSS v3.1

6.1

Medium

VectorAV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions RabbitMQ versions prior to 4.0.3 Tanzu RabbitMQ versions prior to 4.0.3 and 3.13.8
Description RabbitMQ is a messaging and streaming broker. A sophisticated attack could modify the virtual host name on disk, making it unrecoverable and leading to arbitrary JavaScript code execution in the browsers of management UI users. When a virtual host on a RabbitMQ node fails to start, an error message is displayed in the management UI, including the virtual host name, which was not escaped prior to version 4.0.3. An attack that makes a virtual host fail to start and creates a new virtual host name with an XSS code snippet or changes the name of an existing virtual host on disk could trigger arbitrary JavaScript code execution in the management UI.
Recommendations For RabbitMQ versions prior to 4.0.3, update to version 4.0.3 or later to resolve the issue. For Tanzu RabbitMQ versions prior to 4.0.3, update to version 4.0.3 or later to resolve the issue. For Tanzu RabbitMQ versions prior to 3.13.8, update to version 3.13.8 or later to resolve the issue.

Exploit

Fix

RCE

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-59276
AZL-59281
BDU:2025-11493
BIT-RABBITMQ-2025-30219
CVE-2025-30219
GHSA-G58G-82MW-9M3P
OPENSUSE-SU-2025:15291-1
OPENSUSE-SU-2025_1466-1
OPENSUSE-SU-2025_1548-1
OPENSUSE-SU-2026:20082-1
SUSE-SU-2025:01466-1
SUSE-SU-2025:01548-1
SUSE-SU-2025:1466-1
SUSE-SU-2025:1548-1
SUSE-SU-2025_01466-1
SUSE-SU-2025_01548-1
SUSE-SU-2025_1466-1
SUSE-SU-2025_1548-1
SUSE-SU-2026:20126-1
USN-7399-1

Affected Products

Debian
Linuxmint
Rabbitmq
Red Os
Suse
Tanzu Rabbitmq
Ubuntu