Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-9650

Опубликовано: 27 янв. 2015
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 5

Описание

CRLF injection vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the download parameter to api/definitions.

РелизСтатусПримечание
artful

not-affected

3.4.2-2
bionic

not-affected

3.4.2-2
cosmic

not-affected

3.4.2-2
devel

not-affected

3.4.2-2
disco

not-affected

3.4.2-2
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was needed]
esm-infra/bionic

not-affected

3.4.2-2
esm-infra/xenial

not-affected

3.4.2-2
lucid

ignored

end of life
precise

ignored

end of life

Показывать по

EPSS

Процентиль: 55%
0.0032
Низкий

5 Medium

CVSS2

Связанные уязвимости

redhat
больше 11 лет назад

CRLF injection vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the download parameter to api/definitions.

nvd
около 11 лет назад

CRLF injection vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the download parameter to api/definitions.

debian
около 11 лет назад

CRLF injection vulnerability in the management plugin in RabbitMQ 2.1. ...

github
больше 3 лет назад

CRLF injection vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the download parameter to api/definitions.

EPSS

Процентиль: 55%
0.0032
Низкий

5 Medium

CVSS2