Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-57214

Опубликовано: 10 июл. 2026
Источник: redhat
CVSS3: 5.4

Описание

RabbitMQ is a messaging and streaming broker. Prior to 4.2.5, the RabbitMQ management UI renders the x-internal-purpose queue or exchange argument into an HTML title attribute without proper escaping on the Queues and Exchanges pages, allowing a user with permission to declare a queue or exchange to execute JavaScript in another user's browser. This issue is fixed in version 4.2.5.

A flaw was found in RabbitMQ, a messaging and streaming broker. The RabbitMQ management user interface (UI) improperly handles the x-internal-purpose argument when rendering queue or exchange details. This vulnerability allows a user with permissions to declare a queue or exchange to inject and execute arbitrary JavaScript code in another user's browser, leading to a Cross-site Scripting (XSS) attack.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 16.2rabbitmq-serverUnder investigation
Red Hat OpenStack Platform 17.1rabbitmq-serverUnder investigation
Red Hat OpenStack Platform 18.0rabbitmq-serverUnder investigation
Red Hat Hardened Imagesrabbitmq-server4-3-main-4.3.2-1.hum1FixedRHSA-2026:3593906.07.2026
Red Hat Hardened Imagesrabbitmq-server4-2-main-4.2.8-1.hum1FixedRHSA-2026:3594006.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2499213RabbitMQ: RabbitMQ: Cross-site Scripting in management UI allows arbitrary JavaScript execution

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
ubuntu
24 дня назад

RabbitMQ is a messaging and streaming broker. Prior to 4.2.5, the RabbitMQ management UI renders the x-internal-purpose queue or exchange argument into an HTML title attribute without proper escaping on the Queues and Exchanges pages, allowing a user with permission to declare a queue or exchange to execute JavaScript in another user's browser. This issue is fixed in version 4.2.5.

CVSS3: 5.4
nvd
24 дня назад

RabbitMQ is a messaging and streaming broker. Prior to 4.2.5, the RabbitMQ management UI renders the x-internal-purpose queue or exchange argument into an HTML title attribute without proper escaping on the Queues and Exchanges pages, allowing a user with permission to declare a queue or exchange to execute JavaScript in another user's browser. This issue is fixed in version 4.2.5.

CVSS3: 5.4
debian
24 дня назад

RabbitMQ is a messaging and streaming broker. Prior to 4.2.5, the Rabb ...

github
около 2 месяцев назад

Stored XSS in RabbitMQ management UI

5.4 Medium

CVSS3