Описание
RabbitMQ is a messaging and streaming broker. From 3.7.0 to before 4.1.2 and 4.0.13, This vulnerability is fixed in 4.1.2 and 4.0.13.
A flaw was found in RabbitMQ, a messaging and streaming broker.
Unsanitized virtual host names allow for XSS in the the management UI pages that list virtual hosts if the attacker
manages to find a way to force a virtual host to restart. This vulnerability requires high privileges and user interaction, potentially leading to a low impact on confidentiality and integrity.
Отчет
This flaw has a Low impact on Red Hat products. An attacker with high privileges could exploit an unsanitized virtual host name in the RabbitMQ management UI, leading to a Cross-Site Scripting (XSS) vulnerability. Successful exploitation requires user interaction and the ability to force a virtual host restart, limiting the attack surface.
Меры по смягчению последствий
To mitigate this issue, restrict access to the RabbitMQ management UI to trusted administrators only. Ensure that administrative interfaces are not exposed to untrusted networks.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenStack Platform 16.2 | rabbitmq-server | Fix deferred | ||
| Red Hat OpenStack Platform 17.1 | rabbitmq-server | Fix deferred | ||
| Red Hat OpenStack Platform 18.0 | rabbitmq-server | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
3.5 Low
CVSS3
Связанные уязвимости
RabbitMQ is a messaging and streaming broker. From 3.7.0 to before 4.1.2 and 4.0.13, This vulnerability is fixed in 4.1.2 and 4.0.13.
RabbitMQ is a messaging and streaming broker. From 3.7.0 to before 4.1.2 and 4.0.13, This vulnerability is fixed in 4.1.2 and 4.0.13.
RabbitMQ is a messaging and streaming broker. From 3.7.0 to before 4.1 ...
EPSS
3.5 Low
CVSS3