Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-57213

Опубликовано: 10 июл. 2026
Источник: redhat
CVSS3: 5.2
EPSS Низкий

Описание

RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_federation_management plugin renders the consumer_tag field on the Federation Status page without HTML escaping, allowing a user who can configure a federation upstream or policy to execute JavaScript in the browser of a user viewing that page. This issue is fixed in versions 3.13.14, 4.0.19, 4.1.10, and 4.2.5.

A flaw was found in the RabbitMQ rabbitmq_federation_management plugin. This cross-site scripting (XSS) vulnerability occurs because the consumer_tag field on the Federation Status page does not properly escape HTML. A user with permissions to configure a federation upstream or policy can exploit this by injecting malicious JavaScript. When another user views the Federation Status page, the injected script executes in their browser, potentially leading to information disclosure or unauthorized actions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 16.2rabbitmq-serverNot affected
Red Hat OpenStack Platform 17.1rabbitmq-serverNot affected
Red Hat OpenStack Platform 18.0rabbitmq-serverNot affected
Red Hat Hardened Imagesrabbitmq-server4-3-main-4.3.2-1.hum1FixedRHSA-2026:3593906.07.2026
Red Hat Hardened Imagesrabbitmq-server4-2-main-4.2.8-1.hum1FixedRHSA-2026:3594006.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2499208rabbitmq-server: RabbitMQ: Information Disclosure via Cross-Site Scripting in Federation Management

EPSS

Процентиль: 17%
0.00252
Низкий

5.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.8
ubuntu
23 дня назад

RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_federation_management plugin renders the consumer_tag field on the Federation Status page without HTML escaping, allowing a user who can configure a federation upstream or policy to execute JavaScript in the browser of a user viewing that page. This issue is fixed in versions 3.13.14, 4.0.19, 4.1.10, and 4.2.5.

CVSS3: 4.8
nvd
23 дня назад

RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_federation_management plugin renders the consumer_tag field on the Federation Status page without HTML escaping, allowing a user who can configure a federation upstream or policy to execute JavaScript in the browser of a user viewing that page. This issue is fixed in versions 3.13.14, 4.0.19, 4.1.10, and 4.2.5.

CVSS3: 4.8
msrc
19 дней назад

RabbitMQ: Stored XSS federation management plugin via unsanitized consumer_tag rendering

CVSS3: 4.8
debian
23 дня назад

RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19 ...

github
около 2 месяцев назад

Stored XSS in RabbitMQ federation management plugin via unsanitized consumer_tag rendering

EPSS

Процентиль: 17%
0.00252
Низкий

5.2 Medium

CVSS3