Cross-site scripting in RabbitMQ Server - CVE-2025-30219

 

Cross-site scripting in RabbitMQ Server - CVE-2025-30219

Published: March 26, 2025


Vulnerability identifier: #VU106031
CSH Severity: Low
CVSS v4 BT: 1.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear]
CVE-ID: CVE-2025-30219
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data in an error message in Management UI. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


Affected software

RabbitMQ Server
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Server Applications Module
openSUSE Leap
Ubuntu
rabbitmq-server (Ubuntu package)
rabbitmq-server-plugins
erlang-rabbitmq-client
rabbitmq-server
rabbitmq-server313
rabbitmq-server313-bash-completion
rabbitmq-server313-zsh-completion
rabbitmq-server313-plugins
erlang-rabbitmq-client313

How to mitigate CVE-2025-30219

Install updates from vendor's website.

RabbitMQ Server - addressed in versions 3.13.8, 4.0.3
rabbitmq-server (Ubuntu package) - addressed in versions 3.8.3-0ubuntu0.3, 3.9.27-0ubuntu0.2, 3.12.1-1ubuntu1.2, 3.12.1-1ubuntu2.1
rabbitmq-server-plugins - update to 3.8.11-150300.3.19.1
erlang-rabbitmq-client - update to 3.8.11-150300.3.19.1
rabbitmq-server - update to 3.8.11-150300.3.19.1
rabbitmq-server313 - update to 3.13.1-150600.13.8.1
rabbitmq-server313-bash-completion - update to 3.13.1-150600.13.8.1
rabbitmq-server313-zsh-completion - update to 3.13.1-150600.13.8.1
rabbitmq-server313-plugins - update to 3.13.1-150600.13.8.1
erlang-rabbitmq-client313 - update to 3.13.1-150600.13.8.1

External References

Related Security Bulletins