Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-57214

Опубликовано: 10 июл. 2026
Источник: debian
EPSS Низкий

Описание

RabbitMQ is a messaging and streaming broker. Prior to 4.2.5, the RabbitMQ management UI renders the x-internal-purpose queue or exchange argument into an HTML title attribute without proper escaping on the Queues and Exchanges pages, allowing a user with permission to declare a queue or exchange to execute JavaScript in another user's browser. This issue is fixed in version 4.2.5.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
rabbitmq-serverfixed4.3.0-2package
rabbitmq-servernot-affectedtrixiepackage
rabbitmq-servernot-affectedbookwormpackage
rabbitmq-servernot-affectedbullseyepackage

Примечания

  • https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-6jfq-prw2-7rwp

  • https://github.com/rabbitmq/rabbitmq-server/pull/15606

  • https://github.com/rabbitmq/rabbitmq-server/pull/15608

  • https://github.com/rabbitmq/rabbitmq-server/commit/b267a290dd89e42c6e0256f46fc273a8adb7f3ec (v4.3.0-beta.1)

  • https://github.com/rabbitmq/rabbitmq-server/commit/b0027b6c1ae5b869d876e211efe6189ffd92b5c2 (v4.2.5)

EPSS

Процентиль: 32%
0.00387
Низкий

Связанные уязвимости

CVSS3: 5.4
ubuntu
2 месяца назад

RabbitMQ is a messaging and streaming broker. Prior to 4.2.5, the RabbitMQ management UI renders the x-internal-purpose queue or exchange argument into an HTML title attribute without proper escaping on the Queues and Exchanges pages, allowing a user with permission to declare a queue or exchange to execute JavaScript in another user's browser. This issue is fixed in version 4.2.5.

CVSS3: 5.4
redhat
2 месяца назад

RabbitMQ is a messaging and streaming broker. Prior to 4.2.5, the RabbitMQ management UI renders the x-internal-purpose queue or exchange argument into an HTML title attribute without proper escaping on the Queues and Exchanges pages, allowing a user with permission to declare a queue or exchange to execute JavaScript in another user's browser. This issue is fixed in version 4.2.5.

CVSS3: 5.4
nvd
2 месяца назад

RabbitMQ is a messaging and streaming broker. Prior to 4.2.5, the RabbitMQ management UI renders the x-internal-purpose queue or exchange argument into an HTML title attribute without proper escaping on the Queues and Exchanges pages, allowing a user with permission to declare a queue or exchange to execute JavaScript in another user's browser. This issue is fixed in version 4.2.5.

github
3 месяца назад

Stored XSS in RabbitMQ management UI

EPSS

Процентиль: 32%
0.00387
Низкий