CVE-2019-11281
published 2019-10-16CVE-2019-11281: Pivotal RabbitMQ, versions prior to v3.7.18, and RabbitMQ for PCF, versions 1.15.x prior to 1.15.13, versions 1.16.x prior to 1.16.6, and versions 1.17.x prior…
PriorityP422medium4.8CVSS 3.1
AVNACLPRHUIRSCCLILAN
EPSS
1.17%
63.8th percentile
Pivotal RabbitMQ, versions prior to v3.7.18, and RabbitMQ for PCF, versions 1.15.x prior to 1.15.13, versions 1.16.x prior to 1.16.6, and versions 1.17.x prior to 1.17.3, contain two components, the virtual host limits page, and the federation management UI, which do not properly sanitize user input. A remote authenticated malicious user with administrative access could craft a cross site scripting attack that would gain access to virtual hosts and policy management information.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | rabbitmq-server | < rabbitmq-server 3.7.18-1 (bookworm) | rabbitmq-server 3.7.18-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| pivotal | rabbitmq | — | — |
| pivotal | rabbitmq_for_pcf | — | — |
| pivotal | rabbitmq_for_pcf | — | — |
| pivotal | rabbitmq_for_pcf | — | — |
| pivotal_software | rabbitmq | < 3.7.18 | 3.7.18 |
| pivotal_software | rabbitmq | >= 1.15.0 < 1.15.13 | 1.15.13 |
| pivotal_software | rabbitmq | >= 1.16.0 < 1.16.6 | 1.16.6 |
| pivotal_software | rabbitmq | >= 1.17.0 < 1.17.3 | 1.17.3 |
| rabbitmq | rabbitmq-server | >= 0 < 3.7.18-1 | 3.7.18-1 |
| rabbitmq | rabbitmq-server | >= 0 < 3.7.18-1 | 3.7.18-1 |
| rabbitmq | rabbitmq-server | >= 0 < 3.7.18-1 | 3.7.18-1 |
| rabbitmq | rabbitmq-server | >= 0 < 3.7.18-1 | 3.7.18-1 |
| redhat | openstack | — | — |
| redhat | openstack_for_ibm_power | — | — |
CVSS provenance
nvdv3.14.8MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
nvdv3.02.4LOWCVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
osv4.8MEDIUM
vendor_debian4.8LOW
vendor_redhat4.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8v5q-8hwh-h2x8: Pivotal RabbitMQ, versions prior to v3
ghsa_unreviewed·2022-05-24
CVE-2019-11281 [MEDIUM] CWE-79 GHSA-8v5q-8hwh-h2x8: Pivotal RabbitMQ, versions prior to v3
Pivotal RabbitMQ, versions prior to v3.7.18, and RabbitMQ for PCF, versions 1.15.x prior to 1.15.13, versions 1.16.x prior to 1.16.6, and versions 1.17.x prior to 1.17.3, contain two components, the virtual host limits page, and the federation management UI, which do not properly sanitize user input. A remote authenticated malicious user with administrative access could craft a cross site scripting attack that would gain access to virtual hosts and policy management information.
OSV
CVE-2019-11281: Pivotal RabbitMQ, versions prior to v3
osv·2019-10-16·CVSS 4.8
CVE-2019-11281 [MEDIUM] CVE-2019-11281: Pivotal RabbitMQ, versions prior to v3
Pivotal RabbitMQ, versions prior to v3.7.18, and RabbitMQ for PCF, versions 1.15.x prior to 1.15.13, versions 1.16.x prior to 1.16.6, and versions 1.17.x prior to 1.17.3, contain two components, the virtual host limits page, and the federation management UI, which do not properly sanitize user input. A remote authenticated malicious user with administrative access could craft a cross site scripting attack that would gain access to virtual hosts and policy management information.
Red Hat
rabbitmq-server: improper sanitization of vhost limits and federation management UI pages
vendor_redhat·2019-10-14·CVSS 4.8
CVE-2019-11281 [MEDIUM] CWE-79 rabbitmq-server: improper sanitization of vhost limits and federation management UI pages
rabbitmq-server: improper sanitization of vhost limits and federation management UI pages
Pivotal RabbitMQ, versions prior to v3.7.18, and RabbitMQ for PCF, versions 1.15.x prior to 1.15.13, versions 1.16.x prior to 1.16.6, and versions 1.17.x prior to 1.17.3, contain two components, the virtual host limits page, and the federation management UI, which do not properly sanitize user input. A remote authenticated malicious user with administrative access could craft a cross site scripting attack that would gain access to virtual hosts and policy management information.
A vulnerability was found in the rabbitmq-server. User input for the virtual host limits page and the federation management UI was not properly sanitized. A remote, authenticated administrative user could create a cross-site
Debian
CVE-2019-11281: rabbitmq-server - Pivotal RabbitMQ, versions prior to v3.7.18, and RabbitMQ for PCF, versions 1.15...
vendor_debian·2019·CVSS 4.8
CVE-2019-11281 [MEDIUM] CVE-2019-11281: rabbitmq-server - Pivotal RabbitMQ, versions prior to v3.7.18, and RabbitMQ for PCF, versions 1.15...
Pivotal RabbitMQ, versions prior to v3.7.18, and RabbitMQ for PCF, versions 1.15.x prior to 1.15.13, versions 1.16.x prior to 1.16.6, and versions 1.17.x prior to 1.17.3, contain two components, the virtual host limits page, and the federation management UI, which do not properly sanitize user input. A remote authenticated malicious user with administrative access could craft a cross site scripting attack that would gain access to virtual hosts and policy management information.
Scope: local
bookworm: resolved (fixed in 3.7.18-1)
bullseye: resolved (fixed in 3.7.18-1)
forky: resolved (fixed in 3.7.18-1)
sid: resolved (fixed in 3.7.18-1)
trixie: resolved (fixed in 3.7.18-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-11281 rabbitmq-server: improper sanitization of vhost limits and federation management UI pages [fedora-all]
bugzilla·2019-10-31·CVSS 4.8
CVE-2019-11281 [MEDIUM] CVE-2019-11281 rabbitmq-server: improper sanitization of vhost limits and federation management UI pages [fedora-all]
CVE-2019-11281 rabbitmq-server: improper sanitization of vhost limits and federation management UI pages [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this i
Bugzilla
CVE-2019-11281 rabbitmq-server: improper sanitization of vhost limits and federation management UI pages [openstack-rdo]
bugzilla·2019-10-31·CVSS 4.8
CVE-2019-11281 [MEDIUM] CVE-2019-11281 rabbitmq-server: improper sanitization of vhost limits and federation management UI pages [openstack-rdo]
CVE-2019-11281 rabbitmq-server: improper sanitization of vhost limits and federation management UI pages [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discu
Bugzilla
CVE-2019-11281 rabbitmq-server: improper sanitization of vhost limits and federation management UI pages [epel-all]
bugzilla·2019-10-31·CVSS 4.8
CVE-2019-11281 [MEDIUM] CVE-2019-11281 rabbitmq-server: improper sanitization of vhost limits and federation management UI pages [epel-all]
CVE-2019-11281 rabbitmq-server: improper sanitization of vhost limits and federation management UI pages [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2019-11281 rabbitmq-server: improper sanitization of vhost limits and federation management UI pages
bugzilla·2019-10-22·CVSS 4.8
CVE-2019-11281 [MEDIUM] CVE-2019-11281 rabbitmq-server: improper sanitization of vhost limits and federation management UI pages
CVE-2019-11281 rabbitmq-server: improper sanitization of vhost limits and federation management UI pages
Pivotal RabbitMQ, versions prior to v3.7.18, and RabbitMQ for PCF, versions 1.15.x prior to 1.15.13, versions 1.16.x prior to 1.16.6, and versions 1.17.x prior to 1.17.3, contain two components, the virtual host limits page, and the federation management UI, which do not properly sanitize user input. A remote authenticated malicious user with administrative access could craft a cross site scripting attack that would gain access to virtual hosts and policy management information.
References:
https://pivotal.io/security/cve-2019-11281
Discussion:
External References:
https://pivotal.io/security/cve-2019-11281
https://github.com/rabbitmq/rabbitmq-server/releases/tag/v3.7.18
---
Cre
https://access.redhat.com/errata/RHSA-2020:0078https://lists.debian.org/debian-lts-announce/2021/07/msg00011.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EEQ6O7PMNJKYFMQYHAB55L423GYK63SO/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PYTGR3D5FW2O25RXZOTIZMOD2HAUVBE4/https://pivotal.io/security/cve-2019-11281https://access.redhat.com/errata/RHSA-2020:0078https://lists.debian.org/debian-lts-announce/2021/07/msg00011.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EEQ6O7PMNJKYFMQYHAB55L423GYK63SO/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PYTGR3D5FW2O25RXZOTIZMOD2HAUVBE4/https://pivotal.io/security/cve-2019-11281
2019-10-16
Published