Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-9650

Опубликовано: 29 окт. 2014
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

CRLF injection vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the download parameter to api/definitions.

A response-splitting vulnerability was discovered in RabbitMQ. An /api/definitions URL could be specified, which then caused an arbitrary additional header to be returned. A remote attacker could use this flaw to inject arbitrary HTTP headers and possibly gain access to secure data.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 8 (Liberty)rabbitmq-serverAffected
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6rabbitmq-serverFixedRHSA-2016:036808.03.2016
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7rabbitmq-serverFixedRHSA-2016:036908.03.2016
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7rabbitmq-serverFixedRHSA-2016:030829.02.2016
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7rabbitmq-serverFixedRHSA-2016:036708.03.2016

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-113
https://bugzilla.redhat.com/show_bug.cgi?id=1185515RabbitMQ: /api/definitions response splitting vulnerability

EPSS

Процентиль: 55%
0.0032
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
около 11 лет назад

CRLF injection vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the download parameter to api/definitions.

nvd
около 11 лет назад

CRLF injection vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the download parameter to api/definitions.

debian
около 11 лет назад

CRLF injection vulnerability in the management plugin in RabbitMQ 2.1. ...

github
больше 3 лет назад

CRLF injection vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the download parameter to api/definitions.

EPSS

Процентиль: 55%
0.0032
Низкий

4.3 Medium

CVSS2