Логотип exploitDog
bind:CVE-2019-11291
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-11291

Количество 6

Количество 6

ubuntu логотип

CVE-2019-11291

около 6 лет назад

Pivotal RabbitMQ, 3.7 versions prior to v3.7.20 and 3.8 version prior to v3.8.1, and RabbitMQ for PCF, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain two endpoints, federation and shovel, which do not properly sanitize user input. A remote authenticated malicious user with administrative access could craft a cross site scripting attack via the vhost or node name fields that could grant access to virtual hosts and policy management information.

CVSS3: 4.8
EPSS: Низкий
redhat логотип

CVE-2019-11291

около 6 лет назад

Pivotal RabbitMQ, 3.7 versions prior to v3.7.20 and 3.8 version prior to v3.8.1, and RabbitMQ for PCF, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain two endpoints, federation and shovel, which do not properly sanitize user input. A remote authenticated malicious user with administrative access could craft a cross site scripting attack via the vhost or node name fields that could grant access to virtual hosts and policy management information.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2019-11291

около 6 лет назад

Pivotal RabbitMQ, 3.7 versions prior to v3.7.20 and 3.8 version prior to v3.8.1, and RabbitMQ for PCF, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain two endpoints, federation and shovel, which do not properly sanitize user input. A remote authenticated malicious user with administrative access could craft a cross site scripting attack via the vhost or node name fields that could grant access to virtual hosts and policy management information.

CVSS3: 4.8
EPSS: Низкий
debian логотип

CVE-2019-11291

около 6 лет назад

Pivotal RabbitMQ, 3.7 versions prior to v3.7.20 and 3.8 version prior ...

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-9pf7-f47q-mwpq

больше 3 лет назад

Cross-site Scripting in RabbitMQ

CVSS3: 3.5
EPSS: Низкий
fstec логотип

BDU:2023-04781

больше 6 лет назад

Уязвимость компонентов federation и shovel брокера сообщений RabbitMQ, позволяющая нарушителю оказать воздействие на целостность данных

CVSS3: 3.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2019-11291

Pivotal RabbitMQ, 3.7 versions prior to v3.7.20 and 3.8 version prior to v3.8.1, and RabbitMQ for PCF, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain two endpoints, federation and shovel, which do not properly sanitize user input. A remote authenticated malicious user with administrative access could craft a cross site scripting attack via the vhost or node name fields that could grant access to virtual hosts and policy management information.

CVSS3: 4.8
0%
Низкий
около 6 лет назад
redhat логотип
CVE-2019-11291

Pivotal RabbitMQ, 3.7 versions prior to v3.7.20 and 3.8 version prior to v3.8.1, and RabbitMQ for PCF, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain two endpoints, federation and shovel, which do not properly sanitize user input. A remote authenticated malicious user with administrative access could craft a cross site scripting attack via the vhost or node name fields that could grant access to virtual hosts and policy management information.

CVSS3: 3.1
0%
Низкий
около 6 лет назад
nvd логотип
CVE-2019-11291

Pivotal RabbitMQ, 3.7 versions prior to v3.7.20 and 3.8 version prior to v3.8.1, and RabbitMQ for PCF, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain two endpoints, federation and shovel, which do not properly sanitize user input. A remote authenticated malicious user with administrative access could craft a cross site scripting attack via the vhost or node name fields that could grant access to virtual hosts and policy management information.

CVSS3: 4.8
0%
Низкий
около 6 лет назад
debian логотип
CVE-2019-11291

Pivotal RabbitMQ, 3.7 versions prior to v3.7.20 and 3.8 version prior ...

CVSS3: 4.8
0%
Низкий
около 6 лет назад
github логотип
GHSA-9pf7-f47q-mwpq

Cross-site Scripting in RabbitMQ

CVSS3: 3.5
0%
Низкий
больше 3 лет назад
fstec логотип
BDU:2023-04781

Уязвимость компонентов federation и shovel брокера сообщений RabbitMQ, позволяющая нарушителю оказать воздействие на целостность данных

CVSS3: 3.1
0%
Низкий
больше 6 лет назад

Уязвимостей на страницу