Cross-site scripting in RabbitMQ Server - CVE-2025-30219
Published: March 26, 2025
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data in an error message in Management UI. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Server Applications Module
openSUSE Leap
Ubuntu
rabbitmq-server (Ubuntu package)
rabbitmq-server-plugins
erlang-rabbitmq-client
rabbitmq-server
rabbitmq-server313
rabbitmq-server313-bash-completion
rabbitmq-server313-zsh-completion
rabbitmq-server313-plugins
erlang-rabbitmq-client313
How to mitigate CVE-2025-30219
rabbitmq-server (Ubuntu package) - addressed in versions 3.8.3-0ubuntu0.3, 3.9.27-0ubuntu0.2, 3.12.1-1ubuntu1.2, 3.12.1-1ubuntu2.1
rabbitmq-server-plugins - update to 3.8.11-150300.3.19.1
erlang-rabbitmq-client - update to 3.8.11-150300.3.19.1
rabbitmq-server - update to 3.8.11-150300.3.19.1
rabbitmq-server313 - update to 3.13.1-150600.13.8.1
rabbitmq-server313-bash-completion - update to 3.13.1-150600.13.8.1
rabbitmq-server313-zsh-completion - update to 3.13.1-150600.13.8.1
rabbitmq-server313-plugins - update to 3.13.1-150600.13.8.1
erlang-rabbitmq-client313 - update to 3.13.1-150600.13.8.1