Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 11

Количество 11

fstec логотип

BDU:2021-03490

около 5 лет назад

Уязвимость плагина rabbitmq_federation_management брокера сообщений RabbitMQ, позволяющая нарушителю выполнить произвольный код

CVSS3: 4.8
EPSS: Низкий
ubuntu логотип

CVE-2021-32719

около 5 лет назад

RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.18, when a federation link was displayed in the RabbitMQ management UI via the `rabbitmq_federation_management` plugin, its consumer tag was rendered without proper <script> tag sanitization. This potentially allows for JavaScript code execution in the context of the page. The user must be signed in and have elevated permissions (manage federation upstreams and policies) for this to occur. The vulnerability is patched in RabbitMQ 3.8.18. As a workaround, disable the `rabbitmq_federation_management` plugin and use [CLI tools](https://www.rabbitmq.com/cli.html) instead.

CVSS3: 3.1
EPSS: Низкий
redhat логотип

CVE-2021-32719

около 5 лет назад

RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.18, when a federation link was displayed in the RabbitMQ management UI via the `rabbitmq_federation_management` plugin, its consumer tag was rendered without proper <script> tag sanitization. This potentially allows for JavaScript code execution in the context of the page. The user must be signed in and have elevated permissions (manage federation upstreams and policies) for this to occur. The vulnerability is patched in RabbitMQ 3.8.18. As a workaround, disable the `rabbitmq_federation_management` plugin and use [CLI tools](https://www.rabbitmq.com/cli.html) instead.

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2021-32719

около 5 лет назад

RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.18, when a federation link was displayed in the RabbitMQ management UI via the `rabbitmq_federation_management` plugin, its consumer tag was rendered without proper <script> tag sanitization. This potentially allows for JavaScript code execution in the context of the page. The user must be signed in and have elevated permissions (manage federation upstreams and policies) for this to occur. The vulnerability is patched in RabbitMQ 3.8.18. As a workaround, disable the `rabbitmq_federation_management` plugin and use [CLI tools](https://www.rabbitmq.com/cli.html) instead.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2021-32719

около 5 лет назад

RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prio ...

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-5452-hxj4-773x

около 5 лет назад

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in RabbitMQ federation management plugin

CVSS3: 3.1
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:3325-1

почти 5 лет назад

Security update for rabbitmq-server

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:1334-1

почти 5 лет назад

Security update for rabbitmq-server

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:3325-1

почти 5 лет назад

Security update for rabbitmq-server

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:3254-1

почти 5 лет назад

Security update for rabbitmq-server

EPSS: Низкий
suse-cvrf логотип

SUSE-FU-2024:2078-1

около 2 лет назад

Feature update for rabbitmq-server313, erlang26, elixir115

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2021-03490

Уязвимость плагина rabbitmq_federation_management брокера сообщений RabbitMQ, позволяющая нарушителю выполнить произвольный код

CVSS3: 4.8
1%
Низкий
около 5 лет назад
ubuntu логотип
CVE-2021-32719

RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.18, when a federation link was displayed in the RabbitMQ management UI via the `rabbitmq_federation_management` plugin, its consumer tag was rendered without proper <script> tag sanitization. This potentially allows for JavaScript code execution in the context of the page. The user must be signed in and have elevated permissions (manage federation upstreams and policies) for this to occur. The vulnerability is patched in RabbitMQ 3.8.18. As a workaround, disable the `rabbitmq_federation_management` plugin and use [CLI tools](https://www.rabbitmq.com/cli.html) instead.

CVSS3: 3.1
1%
Низкий
около 5 лет назад
redhat логотип
CVE-2021-32719

RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.18, when a federation link was displayed in the RabbitMQ management UI via the `rabbitmq_federation_management` plugin, its consumer tag was rendered without proper <script> tag sanitization. This potentially allows for JavaScript code execution in the context of the page. The user must be signed in and have elevated permissions (manage federation upstreams and policies) for this to occur. The vulnerability is patched in RabbitMQ 3.8.18. As a workaround, disable the `rabbitmq_federation_management` plugin and use [CLI tools](https://www.rabbitmq.com/cli.html) instead.

CVSS3: 4.8
1%
Низкий
около 5 лет назад
nvd логотип
CVE-2021-32719

RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.18, when a federation link was displayed in the RabbitMQ management UI via the `rabbitmq_federation_management` plugin, its consumer tag was rendered without proper <script> tag sanitization. This potentially allows for JavaScript code execution in the context of the page. The user must be signed in and have elevated permissions (manage federation upstreams and policies) for this to occur. The vulnerability is patched in RabbitMQ 3.8.18. As a workaround, disable the `rabbitmq_federation_management` plugin and use [CLI tools](https://www.rabbitmq.com/cli.html) instead.

CVSS3: 3.1
1%
Низкий
около 5 лет назад
debian логотип
CVE-2021-32719

RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prio ...

CVSS3: 3.1
1%
Низкий
около 5 лет назад
github логотип
GHSA-5452-hxj4-773x

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in RabbitMQ federation management plugin

CVSS3: 3.1
1%
Низкий
около 5 лет назад
suse-cvrf логотип
openSUSE-SU-2021:3325-1

Security update for rabbitmq-server

почти 5 лет назад
suse-cvrf логотип
openSUSE-SU-2021:1334-1

Security update for rabbitmq-server

почти 5 лет назад
suse-cvrf логотип
SUSE-SU-2021:3325-1

Security update for rabbitmq-server

почти 5 лет назад
suse-cvrf логотип
SUSE-SU-2021:3254-1

Security update for rabbitmq-server

почти 5 лет назад
suse-cvrf логотип
SUSE-FU-2024:2078-1

Feature update for rabbitmq-server313, erlang26, elixir115

около 2 лет назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.