Cross-site scripting in RabbitMQ - CVE-2017-4965

 

Cross-site scripting in RabbitMQ - CVE-2017-4965

Published: June 13, 2017 / Updated: August 8, 2020


Vulnerability identifier: #VU38873
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2017-4965
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to 1.6.18, and 1.7.x versions prior to 1.7.15. Several forms in the RabbitMQ management UI are vulnerable to XSS attacks.


Affected software

RabbitMQ

How to mitigate CVE-2017-4965

Install update from vendor's website.


External References

Related Security Bulletins