Debian Rabbitmq-Server vulnerabilities
20 known vulnerabilities affecting debian/rabbitmq-server.
Total CVEs
20
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH3MEDIUM8LOW8
Vulnerabilities
Page 1 of 1
CVE-2016-9877P3CRITICALCVSS 9.8fixed in rabbitmq-server 3.6.6-1 (bookworm)2016
CVE-2016-9877 [CRITICAL] CVE-2016-9877: rabbitmq-server - An issue was discovered in Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before 3....
An issue was discovered in Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before 3.6.6 and RabbitMQ for PCF 1.5.x before 1.5.20, 1.6.x before 1.6.12, and 1.7.x before 1.7.7. MQTT (MQ Telemetry Transport) connection authentication with a username/password pair succeeds if an existing username is provided but the password is omitted from the connection request.
debian
CVE-2021-22116P3HIGHCVSS 7.5fixed in rabbitmq-server 3.9.4-1 (bookworm)2021
CVE-2021-22116 [HIGH] CVE-2021-22116: rabbitmq-server - RabbitMQ all versions prior to 3.8.16 are prone to a denial of service vulnerabi...
RabbitMQ all versions prior to 3.8.16 are prone to a denial of service vulnerability due to improper input validation in AMQP 1.0 client connection endpoint. A malicious user can exploit the vulnerability by sending malicious AMQP messages to the target RabbitMQ instance having the AMQP 1.0 plugin enabled.
Scope: local
bookworm: resolved (fixed in 3.9.4-1)
b
debian
CVE-2019-11287P3HIGHCVSS 7.5fixed in rabbitmq-server 3.8.3-1 (bookworm)2019
CVE-2019-11287 [HIGH] CVE-2019-11287: rabbitmq-server - Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and R...
Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is vulnerable to a denial of service attack. The "X-Reason" HTTP Header can be leveraged to insert a malicious Erlang format string that will ex
debian
CVE-2022-31008P3MEDIUMCVSS 5.5fixed in rabbitmq-server 3.10.8-1 (bookworm)2022
CVE-2022-31008 [MEDIUM] CVE-2022-31008: rabbitmq-server - RabbitMQ is a multi-protocol messaging and streaming broker. In affected version...
RabbitMQ is a multi-protocol messaging and streaming broker. In affected versions the shovel and federation plugins perform URI obfuscation in their worker (link) state. The encryption key used to encrypt the URI was seeded with a predictable secret. This means that in case of certain exceptions related to Shovel and Federation plugins, reasonably easily d
debian
CVE-2017-4966P3LOWCVSS 7.8fixed in rabbitmq-server 3.6.10-1 (bookworm)2017
CVE-2017-4966 [HIGH] CVE-2017-4966: rabbitmq-server - An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, ...
An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to 1.6.18, and 1.7.x versions prior to 1.7.15. RabbitMQ management UI stores signed-in user credentials in a browser's local storage without expirati
debian
CVE-2018-1279P4HIGHCVSS 8.5fixed in rabbitmq-server 3.9.8-5 (bookworm)2018
CVE-2018-1279 [HIGH] CVE-2018-1279: rabbitmq-server - Pivotal RabbitMQ for PCF, all versions, uses a deterministically generated cooki...
Pivotal RabbitMQ for PCF, all versions, uses a deterministically generated cookie that is shared between all machines when configured in a multi-tenant cluster. A remote attacker who can gain information about the network topology can guess this cookie and, if they have access to the right ports on any server in the MQ cluster can use this cookie to gain full
debian
CVE-2017-4965P4LOWCVSS 6.1fixed in rabbitmq-server 3.6.10-1 (bookworm)2017
CVE-2017-4965 [MEDIUM] CVE-2017-4965: rabbitmq-server - An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, ...
An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to 1.6.18, and 1.7.x versions prior to 1.7.15. Several forms in the RabbitMQ management UI are vulnerable to XSS attacks.
Scope: local
bookworm: re
debian
CVE-2014-9494P4MEDIUMCVSS 5.0fixed in rabbitmq-server 3.4.1-1 (bookworm)2014
CVE-2014-9494 [MEDIUM] CVE-2014-9494: rabbitmq-server - RabbitMQ before 3.4.0 allows remote attackers to bypass the loopback_users restr...
RabbitMQ before 3.4.0 allows remote attackers to bypass the loopback_users restriction via a crafted X-Forwareded-For header.
Scope: local
bookworm: resolved (fixed in 3.4.1-1)
bullseye: resolved (fixed in 3.4.1-1)
forky: resolved (fixed in 3.4.1-1)
sid: resolved (fixed in 3.4.1-1)
trixie: resolved (fixed in 3.4.1-1)
debian
CVE-2015-8786P4MEDIUMCVSS 6.5fixed in rabbitmq-server 3.6.5-1 (bookworm)2015
CVE-2015-8786 [MEDIUM] CVE-2015-8786: rabbitmq-server - The Management plugin in RabbitMQ before 3.6.1 allows remote authenticated users...
The Management plugin in RabbitMQ before 3.6.1 allows remote authenticated users with certain privileges to cause a denial of service (resource consumption) via the (1) lengths_age or (2) lengths_incr parameter.
Scope: local
bookworm: resolved (fixed in 3.6.5-1)
bullseye: resolved (fixed in 3.6.5-1)
forky: resolved (fixed in 3.6.5-1)
sid: resolved (fixed in
debian
CVE-2017-4967P4LOWCVSS 6.1fixed in rabbitmq-server 3.6.10-1 (bookworm)2017
CVE-2017-4967 [MEDIUM] CVE-2017-4967: rabbitmq-server - An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, ...
An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to 1.6.18, and 1.7.x versions prior to 1.7.15. Several forms in the RabbitMQ management UI are vulnerable to XSS attacks.
Scope: local
bookworm: re
debian
CVE-2025-50200P4LOWCVSS 6.7fixed in rabbitmq-server 4.0.5-9 (forky)2025
CVE-2025-50200 [MEDIUM] CVE-2025-50200: rabbitmq-server - RabbitMQ is a messaging and streaming broker. In versions 3.13.7 and prior, Rabb...
RabbitMQ is a messaging and streaming broker. In versions 3.13.7 and prior, RabbitMQ is logging authorization headers in plaintext encoded in base64. When querying RabbitMQ api with HTTP/s with basic authentication it creates logs with all headers in request, including authorization headers which show base64 encoded username:password. This is easy to decod
debian
CVE-2025-30219P4MEDIUMCVSS 6.1fixed in rabbitmq-server 4.0.5-1 (forky)2025
CVE-2025-30219 [MEDIUM] CVE-2025-30219: rabbitmq-server - RabbitMQ is a messaging and streaming broker. Versions prior to 4.0.3 are vulner...
RabbitMQ is a messaging and streaming broker. Versions prior to 4.0.3 are vulnerable to a sophisticated attack that could modify virtual host name on disk and then make it unrecoverable (with other on disk file modifications) can lead to arbitrary JavaScript code execution in the browsers of management UI users. When a virtual host on a RabbitMQ node fails
debian
CVE-2021-32718P4LOWCVSS 3.1fixed in rabbitmq-server 3.9.4-1 (bookworm)2021
CVE-2021-32718 [LOW] CVE-2021-32718: rabbitmq-server - RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to versi...
RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.17, a new user being added via management UI could lead to the user's bane being rendered in a confirmation message without proper `` tag sanitization, potentially allowing for JavaScript code execution in the context of the page. In order for this to occur, the user must b
debian
CVE-2014-9650P4MEDIUMCVSS 5.0fixed in rabbitmq-server 3.4.1-1 (bookworm)2014
CVE-2014-9650 [MEDIUM] CVE-2014-9650: rabbitmq-server - CRLF injection vulnerability in the management plugin in RabbitMQ 2.1.0 through ...
CRLF injection vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the download parameter to api/definitions.
Scope: local
bookworm: resolved (fixed in 3.4.1-1)
bullseye: resolved (fixed in 3.4.1-1)
forky: resolved (fixed i
debian
CVE-2023-46118P4MEDIUMCVSS 4.9fixed in rabbitmq-server 3.10.8-1.1+deb12u1 (bookworm)2023
CVE-2023-46118 [MEDIUM] CVE-2023-46118: rabbitmq-server - RabbitMQ is a multi-protocol messaging and streaming broker. HTTP API did not en...
RabbitMQ is a multi-protocol messaging and streaming broker. HTTP API did not enforce an HTTP request body limit, making it vulnerable for denial of service (DoS) attacks with very large messages. An authenticated user with sufficient credentials can publish a very large messages over the HTTP API and cause target node to be terminated by an "out-of-memory
debian
CVE-2019-11281P4LOWCVSS 4.8fixed in rabbitmq-server 3.7.18-1 (bookworm)2019
CVE-2019-11281 [MEDIUM] CVE-2019-11281: rabbitmq-server - Pivotal RabbitMQ, versions prior to v3.7.18, and RabbitMQ for PCF, versions 1.15...
Pivotal RabbitMQ, versions prior to v3.7.18, and RabbitMQ for PCF, versions 1.15.x prior to 1.15.13, versions 1.16.x prior to 1.16.6, and versions 1.17.x prior to 1.17.3, contain two components, the virtual host limits page, and the federation management UI, which do not properly sanitize user input. A remote authenticated malicious user with administrativ
debian
CVE-2021-32719P4LOWCVSS 3.1fixed in rabbitmq-server 3.9.4-1 (bookworm)2021
CVE-2021-32719 [LOW] CVE-2021-32719: rabbitmq-server - RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to versi...
RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.18, when a federation link was displayed in the RabbitMQ management UI via the `rabbitmq_federation_management` plugin, its consumer tag was rendered without proper tag sanitization. This potentially allows for JavaScript code execution in the context of the page. The user
debian
CVE-2019-11291P4MEDIUMCVSS 4.8fixed in rabbitmq-server 3.8.3-1 (bookworm)2019
CVE-2019-11291 [MEDIUM] CVE-2019-11291: rabbitmq-server - Pivotal RabbitMQ, 3.7 versions prior to v3.7.20 and 3.8 version prior to v3.8.1,...
Pivotal RabbitMQ, 3.7 versions prior to v3.7.20 and 3.8 version prior to v3.8.1, and RabbitMQ for PCF, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain two endpoints, federation and shovel, which do not properly sanitize user input. A remote authenticated malicious user with administrative access could craft a cross site scripti
debian
CVE-2014-9649P4MEDIUMCVSS 4.3fixed in rabbitmq-server 3.4.1-1 (bookworm)2014
CVE-2014-9649 [MEDIUM] CVE-2014-9649: rabbitmq-server - Cross-site scripting (XSS) vulnerability in the management plugin in RabbitMQ 2....
Cross-site scripting (XSS) vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows remote attackers to inject arbitrary web script or HTML via the path info to api/, which is not properly handled in an error message.
Scope: local
bookworm: resolved (fixed in 3.4.1-1)
bullseye: resolved (fixed in 3.4.1-1)
forky: resolved (fi
debian
CVE-2015-0862P4LOWCVSS 3.5fixed in rabbitmq-server 3.4.3-1 (bookworm)2015
CVE-2015-0862 [LOW] CVE-2015-0862: rabbitmq-server - Multiple cross-site scripting (XSS) vulnerabilities in the management web UI in ...
Multiple cross-site scripting (XSS) vulnerabilities in the management web UI in the RabbitMQ management plugin before 3.4.3 allow remote authenticated users to inject arbitrary web script or HTML via (1) message details when a message is unqueued, such as headers or arguments; (2) policy names, which are not properly handled when viewing policies; (3) details f
debian