Cross-site scripting in RabbitMQ - CVE-2017-4967

 

Cross-site scripting in RabbitMQ - CVE-2017-4967

Published: June 13, 2017 / Updated: August 8, 2020


Vulnerability identifier: #VU38875
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2017-4967
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to 1.6.18, and 1.7.x versions prior to 1.7.15. Several forms in the RabbitMQ management UI are vulnerable to XSS attacks.


Affected software

RabbitMQ

How to mitigate CVE-2017-4967

Install update from vendor's website.


External References

Related Security Bulletins