Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-57214

Опубликовано: 10 июл. 2026
Источник: debian
EPSS Низкий

Описание

RabbitMQ is a messaging and streaming broker. Prior to 4.2.5, the RabbitMQ management UI renders the x-internal-purpose queue or exchange argument into an HTML title attribute without proper escaping on the Queues and Exchanges pages, allowing a user with permission to declare a queue or exchange to execute JavaScript in another user's browser. This issue is fixed in version 4.2.5.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
rabbitmq-serverfixed4.3.0-2package

Примечания

  • https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-6jfq-prw2-7rwp

  • https://github.com/rabbitmq/rabbitmq-server/pull/15606

  • https://github.com/rabbitmq/rabbitmq-server/pull/15608

  • https://github.com/rabbitmq/rabbitmq-server/commit/b267a290dd89e42c6e0256f46fc273a8adb7f3ec (v4.3.0-beta.1)

  • https://github.com/rabbitmq/rabbitmq-server/commit/b0027b6c1ae5b869d876e211efe6189ffd92b5c2 (v4.2.5)

EPSS

Процентиль: 13%
0.0022
Низкий

Связанные уязвимости

CVSS3: 5.4
ubuntu
24 дня назад

RabbitMQ is a messaging and streaming broker. Prior to 4.2.5, the RabbitMQ management UI renders the x-internal-purpose queue or exchange argument into an HTML title attribute without proper escaping on the Queues and Exchanges pages, allowing a user with permission to declare a queue or exchange to execute JavaScript in another user's browser. This issue is fixed in version 4.2.5.

CVSS3: 5.4
redhat
25 дней назад

RabbitMQ is a messaging and streaming broker. Prior to 4.2.5, the RabbitMQ management UI renders the x-internal-purpose queue or exchange argument into an HTML title attribute without proper escaping on the Queues and Exchanges pages, allowing a user with permission to declare a queue or exchange to execute JavaScript in another user's browser. This issue is fixed in version 4.2.5.

CVSS3: 5.4
nvd
24 дня назад

RabbitMQ is a messaging and streaming broker. Prior to 4.2.5, the RabbitMQ management UI renders the x-internal-purpose queue or exchange argument into an HTML title attribute without proper escaping on the Queues and Exchanges pages, allowing a user with permission to declare a queue or exchange to execute JavaScript in another user's browser. This issue is fixed in version 4.2.5.

github
около 2 месяцев назад

Stored XSS in RabbitMQ management UI

EPSS

Процентиль: 13%
0.0022
Низкий