CVE-2014-9494
published 2015-01-20CVE-2014-9494: RabbitMQ before 3.4.0 allows remote attackers to bypass the loopback_users restriction via a crafted X-Forwareded-For header.
PriorityP430medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
1.39%
69.3th percentile
RabbitMQ before 3.4.0 allows remote attackers to bypass the loopback_users restriction via a crafted X-Forwareded-For header.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rabbitmq-server | < rabbitmq-server 3.4.1-1 (bookworm) | rabbitmq-server 3.4.1-1 (bookworm) |
| pivotal_software | rabbitmq | <= 3.3.5 | — |
| rabbitmq | rabbitmq-server | >= 0 < 3.4.1-1 | 3.4.1-1 |
| rabbitmq | rabbitmq-server | >= 0 < 3.4.1-1 | 3.4.1-1 |
| rabbitmq | rabbitmq-server | >= 0 < 3.4.1-1 | 3.4.1-1 |
| rabbitmq | rabbitmq-server | >= 0 < 3.4.1-1 | 3.4.1-1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
rabbitmq-server: insufficient 'X-Forwarded-For' header validation
vendor_redhat·2014-10-15·CVSS 5.0
CVE-2014-9494 [MEDIUM] CWE-20 rabbitmq-server: insufficient 'X-Forwarded-For' header validation
rabbitmq-server: insufficient 'X-Forwarded-For' header validation
RabbitMQ before 3.4.0 allows remote attackers to bypass the loopback_users restriction via a crafted X-Forwareded-For header.
Package: rabbitmq-server (Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)) - Not affected
Package: rabbitmq-server (Red Hat Enterprise Linux OpenStack Platform 6 (Juno)) - Fix deferred
Debian
CVE-2014-9494: rabbitmq-server - RabbitMQ before 3.4.0 allows remote attackers to bypass the loopback_users restr...
vendor_debian·2014·CVSS 5.0
CVE-2014-9494 [MEDIUM] CVE-2014-9494: rabbitmq-server - RabbitMQ before 3.4.0 allows remote attackers to bypass the loopback_users restr...
RabbitMQ before 3.4.0 allows remote attackers to bypass the loopback_users restriction via a crafted X-Forwareded-For header.
Scope: local
bookworm: resolved (fixed in 3.4.1-1)
bullseye: resolved (fixed in 3.4.1-1)
forky: resolved (fixed in 3.4.1-1)
sid: resolved (fixed in 3.4.1-1)
trixie: resolved (fixed in 3.4.1-1)
GHSA
GHSA-rgxx-9mfj-x5rf: RabbitMQ before 3
ghsa_unreviewed·2022-05-14
CVE-2014-9494 [MEDIUM] GHSA-rgxx-9mfj-x5rf: RabbitMQ before 3
RabbitMQ before 3.4.0 allows remote attackers to bypass the loopback_users restriction via a crafted X-Forwareded-For header.
OSV
CVE-2014-9494: RabbitMQ before 3
osv·2015-01-20·CVSS 5.0
CVE-2014-9494 [MEDIUM] CVE-2014-9494: RabbitMQ before 3
RabbitMQ before 3.4.0 allows remote attackers to bypass the loopback_users restriction via a crafted X-Forwareded-For header.
No detection rules found.
No public exploits indexed.
http://seclists.org/oss-sec/2015/q1/30http://www.rabbitmq.com/release-notes/README-3.4.0.txthttps://exchange.xforce.ibmcloud.com/vulnerabilities/99685https://groups.google.com/forum/#%21topic/rabbitmq-users/DMkypbSvIyMhttp://seclists.org/oss-sec/2015/q1/30http://www.rabbitmq.com/release-notes/README-3.4.0.txthttps://exchange.xforce.ibmcloud.com/vulnerabilities/99685https://groups.google.com/forum/#%21topic/rabbitmq-users/DMkypbSvIyM
2015-01-20
Published