5
CVSSv2

CVE-2014-9494

Published: 20/01/2015 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

RabbitMQ prior to 3.4.0 allows remote malicious users to bypass the loopback_users restriction via a crafted X-Forwareded-For header.

Vulnerable Product Search on Vulmon Subscribe to Product

pivotal software rabbitmq

Vendor Advisories

Debian Bug report logs - #773134 rabbitmq-server: CVE-2014-9494: rabbitmq_management incorrectly trusts 'X-Forwarded-For' header Package: rabbitmq-server; Maintainer for rabbitmq-server is Debian OpenStack <team+openstack@trackerdebianorg>; Source for rabbitmq-server is src:rabbitmq-server (PTS, buildd, popcon) Reported by ...
RabbitMQ before 340 allows remote attackers to bypass the loopback_users restriction via a crafted X-Forwareded-For header ...