Логотип exploitDog
bind:"CVE-2021-32719"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2021-32719"

Количество 10

Количество 10

ubuntu логотип

CVE-2021-32719

больше 4 лет назад

RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.18, when a federation link was displayed in the RabbitMQ management UI via the `rabbitmq_federation_management` plugin, its consumer tag was rendered without proper <script> tag sanitization. This potentially allows for JavaScript code execution in the context of the page. The user must be signed in and have elevated permissions (manage federation upstreams and policies) for this to occur. The vulnerability is patched in RabbitMQ 3.8.18. As a workaround, disable the `rabbitmq_federation_management` plugin and use [CLI tools](https://www.rabbitmq.com/cli.html) instead.

CVSS3: 3.1
EPSS: Низкий
redhat логотип

CVE-2021-32719

больше 4 лет назад

RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.18, when a federation link was displayed in the RabbitMQ management UI via the `rabbitmq_federation_management` plugin, its consumer tag was rendered without proper <script> tag sanitization. This potentially allows for JavaScript code execution in the context of the page. The user must be signed in and have elevated permissions (manage federation upstreams and policies) for this to occur. The vulnerability is patched in RabbitMQ 3.8.18. As a workaround, disable the `rabbitmq_federation_management` plugin and use [CLI tools](https://www.rabbitmq.com/cli.html) instead.

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2021-32719

больше 4 лет назад

RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.18, when a federation link was displayed in the RabbitMQ management UI via the `rabbitmq_federation_management` plugin, its consumer tag was rendered without proper <script> tag sanitization. This potentially allows for JavaScript code execution in the context of the page. The user must be signed in and have elevated permissions (manage federation upstreams and policies) for this to occur. The vulnerability is patched in RabbitMQ 3.8.18. As a workaround, disable the `rabbitmq_federation_management` plugin and use [CLI tools](https://www.rabbitmq.com/cli.html) instead.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2021-32719

больше 4 лет назад

RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prio ...

CVSS3: 3.1
EPSS: Низкий
fstec логотип

BDU:2021-03490

больше 4 лет назад

Уязвимость плагина rabbitmq_federation_management брокера сообщений RabbitMQ, позволяющая нарушителю выполнить произвольный код

CVSS3: 4.8
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:3325-1

больше 4 лет назад

Security update for rabbitmq-server

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:1334-1

больше 4 лет назад

Security update for rabbitmq-server

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:3325-1

больше 4 лет назад

Security update for rabbitmq-server

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:3254-1

больше 4 лет назад

Security update for rabbitmq-server

EPSS: Низкий
suse-cvrf логотип

SUSE-FU-2024:2078-1

больше 1 года назад

Feature update for rabbitmq-server313, erlang26, elixir115

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2021-32719

RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.18, when a federation link was displayed in the RabbitMQ management UI via the `rabbitmq_federation_management` plugin, its consumer tag was rendered without proper <script> tag sanitization. This potentially allows for JavaScript code execution in the context of the page. The user must be signed in and have elevated permissions (manage federation upstreams and policies) for this to occur. The vulnerability is patched in RabbitMQ 3.8.18. As a workaround, disable the `rabbitmq_federation_management` plugin and use [CLI tools](https://www.rabbitmq.com/cli.html) instead.

CVSS3: 3.1
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2021-32719

RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.18, when a federation link was displayed in the RabbitMQ management UI via the `rabbitmq_federation_management` plugin, its consumer tag was rendered without proper <script> tag sanitization. This potentially allows for JavaScript code execution in the context of the page. The user must be signed in and have elevated permissions (manage federation upstreams and policies) for this to occur. The vulnerability is patched in RabbitMQ 3.8.18. As a workaround, disable the `rabbitmq_federation_management` plugin and use [CLI tools](https://www.rabbitmq.com/cli.html) instead.

CVSS3: 4.8
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-32719

RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.18, when a federation link was displayed in the RabbitMQ management UI via the `rabbitmq_federation_management` plugin, its consumer tag was rendered without proper <script> tag sanitization. This potentially allows for JavaScript code execution in the context of the page. The user must be signed in and have elevated permissions (manage federation upstreams and policies) for this to occur. The vulnerability is patched in RabbitMQ 3.8.18. As a workaround, disable the `rabbitmq_federation_management` plugin and use [CLI tools](https://www.rabbitmq.com/cli.html) instead.

CVSS3: 3.1
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-32719

RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prio ...

CVSS3: 3.1
0%
Низкий
больше 4 лет назад
fstec логотип
BDU:2021-03490

Уязвимость плагина rabbitmq_federation_management брокера сообщений RabbitMQ, позволяющая нарушителю выполнить произвольный код

CVSS3: 4.8
0%
Низкий
больше 4 лет назад
suse-cvrf логотип
openSUSE-SU-2021:3325-1

Security update for rabbitmq-server

больше 4 лет назад
suse-cvrf логотип
openSUSE-SU-2021:1334-1

Security update for rabbitmq-server

больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:3325-1

Security update for rabbitmq-server

больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2021:3254-1

Security update for rabbitmq-server

больше 4 лет назад
suse-cvrf логотип
SUSE-FU-2024:2078-1

Feature update for rabbitmq-server313, erlang26, elixir115

больше 1 года назад

Уязвимостей на страницу