Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-9650

Опубликовано: 27 янв. 2015
Источник: debian

Описание

CRLF injection vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the download parameter to api/definitions.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
rabbitmq-serverfixed3.4.1-1package
rabbitmq-serverno-dsajessiepackage
rabbitmq-serverno-dsawheezypackage
rabbitmq-servernot-affectedsqueezepackage

Примечания

  • https://groups.google.com/forum/#!topic/rabbitmq-users/-3Z2FyGtXhs

  • Fixed by: https://github.com/rabbitmq/rabbitmq-management/commit/b5a5fc31bd49ad821a655ea9e2fe920d670a62ad

  • https://www.openwall.com/lists/oss-security/2015/01/21/13

Связанные уязвимости

ubuntu
около 11 лет назад

CRLF injection vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the download parameter to api/definitions.

redhat
больше 11 лет назад

CRLF injection vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the download parameter to api/definitions.

nvd
около 11 лет назад

CRLF injection vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the download parameter to api/definitions.

github
больше 3 лет назад

CRLF injection vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the download parameter to api/definitions.