CVE-2021-32719
published 2021-06-28CVE-2021-32719: RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.18, when a federation link was displayed in the RabbitMQ management UI…
PriorityP422medium4.8CVSS 3.1
AVNACLPRHUIRSCCLILAN
EPSS
1.42%
69.7th percentile
RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.18, when a federation link was displayed in the RabbitMQ management UI via the `rabbitmq_federation_management` plugin, its consumer tag was rendered without proper tag sanitization. This potentially allows for JavaScript code execution in the context of the page. The user must be signed in and have elevated permissions (manage federation upstreams and policies) for this to occur. The vulnerability is patched in RabbitMQ 3.8.18. As a workaround, disable the `rabbitmq_federation_management` plugin and use [CLI tools](https://www.rabbitmq.com/cli.html) instead.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rabbitmq-server | < rabbitmq-server 3.9.4-1 (bookworm) | rabbitmq-server 3.9.4-1 (bookworm) |
| rabbitmq | rabbitmq-server | < 3.8.18 | 3.8.18 |
| rabbitmq | rabbitmq-server | >= 0 < 3.9.4-1 | 3.9.4-1 |
| rabbitmq | rabbitmq-server | >= 0 < 3.9.4-1 | 3.9.4-1 |
| rabbitmq | rabbitmq-server | >= 0 < 3.9.4-1 | 3.9.4-1 |
| rabbitmq | rabbitmq-server | >= 0 < 3.8.3-0ubuntu0.2 | 3.8.3-0ubuntu0.2 |
| vmware | rabbitmq | < 3.8.18 | 3.8.18 |
CVSS provenance
nvdv3.14.8MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
osv5.4MEDIUM
vendor_debian3.1LOW
vendor_redhat3.1LOW
vendor_ubuntu3.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
rabbitmq-server vulnerabilities
osv·2024-12-09·CVSS 5.4
CVE-2021-32718 [MEDIUM] rabbitmq-server vulnerabilities
rabbitmq-server vulnerabilities
Christian Rellmann discovered that RabbitMQ Server did not properly
sanitize user input when adding a new user via the management UI. An
attacker could possibly use this issue to perform cross site scripting and
obtain sensitive information. (CVE-2021-32718)
Fahimhusain Raydurg discovered that RabbitMQ Server did not properly
sanitize user input when using the federation management plugin. An
attacker could possibly use this issue to perform cross site scripting and
obtain sensitive information. (CVE-2021-32719)
OSV
CVE-2021-32719: RabbitMQ is a multi-protocol messaging broker
osv·2021-06-28·CVSS 4.8
CVE-2021-32719 [MEDIUM] CVE-2021-32719: RabbitMQ is a multi-protocol messaging broker
RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.18, when a federation link was displayed in the RabbitMQ management UI via the `rabbitmq_federation_management` plugin, its consumer tag was rendered without proper tag sanitization. This potentially allows for JavaScript code execution in the context of the page. The user must be signed in and have elevated permissions (manage federation upstreams and policies) for this to occur. The vulnerability is patched in RabbitMQ 3.8.18. As a workaround, disable the `rabbitmq_federation_management` plugin and use [CLI tools](https://www.rabbitmq.com/cli.html) instead.
Ubuntu
RabbitMQ Server vulnerabilities
vendor_ubuntu·2024-12-09·CVSS 3.1
CVE-2021-32719 [LOW] RabbitMQ Server vulnerabilities
Title: RabbitMQ Server vulnerabilities
Summary: RabbitMQ Server could be made to expose sensitive information over the
network.
Christian Rellmann discovered that RabbitMQ Server did not properly
sanitize user input when adding a new user via the management UI. An
attacker could possibly use this issue to perform cross site scripting and
obtain sensitive information. (CVE-2021-32718)
Fahimhusain Raydurg discovered that RabbitMQ Server did not properly
sanitize user input when using the federation management plugin. An
attacker could possibly use this issue to perform cross site scripting and
obtain sensitive information. (CVE-2021-32719)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
rabbitmq-server: improper neutralization of script-related HTML tags in a web page (basic XSS) in federation management plugin
vendor_redhat·2021-06-19·CVSS 3.1
CVE-2021-32719 [LOW] CWE-79 rabbitmq-server: improper neutralization of script-related HTML tags in a web page (basic XSS) in federation management plugin
rabbitmq-server: improper neutralization of script-related HTML tags in a web page (basic XSS) in federation management plugin
RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.18, when a federation link was displayed in the RabbitMQ management UI via the `rabbitmq_federation_management` plugin, its consumer tag was rendered without proper tag sanitization. This potentially allows for JavaScript code execution in the context of the page. The user must be signed in and have elevated permissions (manage federation upstreams and policies) for this to occur. The vulnerability is patched in RabbitMQ 3.8.18. As a workaround, disable the `rabbitmq_federation_management` plugin and use [CLI tools](https://www.rabbitmq.com/cli.html) instead.
Statement: Red Hat
Debian
CVE-2021-32719: rabbitmq-server - RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to versi...
vendor_debian·2021·CVSS 3.1
CVE-2021-32719 [LOW] CVE-2021-32719: rabbitmq-server - RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to versi...
RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.18, when a federation link was displayed in the RabbitMQ management UI via the `rabbitmq_federation_management` plugin, its consumer tag was rendered without proper tag sanitization. This potentially allows for JavaScript code execution in the context of the page. The user must be signed in and have elevated permissions (manage federation upstreams and policies) for this to occur. The vulnerability is patched in RabbitMQ 3.8.18. As a workaround, disable the `rabbitmq_federation_management` plugin and use [CLI tools](https://www.rabbitmq.com/cli.html) instead.
Scope: local
bookworm: resolved (fixed in 3.9.4-1)
bullseye: open
forky: resolved (fixed in 3.9.4-1)
sid: resolved (fixed in 3.9.4-1)
trixie: resol
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/rabbitmq/rabbitmq-server/pull/3122https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-5452-hxj4-773xhttps://herolab.usd.de/security-advisories/usd-2021-0011/https://github.com/rabbitmq/rabbitmq-server/pull/3122https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-5452-hxj4-773xhttps://herolab.usd.de/security-advisories/usd-2021-0011/
2021-06-28
Published