Pivotal RabbitMQ, 3.7 versions prior to v3.7.20 and 3.8 version prior to v3.8.1, and RabbitMQ for PCF, 1.16.x versions before 1.16.7 and 1.17.x versions before 1.17.4, contain two endpoints, federation and shovel, which do not properly sanitize user input. A remote authenticated malicious user with administrative access could craft a cross site scripting attack via the vhost or node name fields that could grant access to virtual hosts and policy management information.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
vmware rabbitmq |
||
vmware rabbitmq 3.8.0 |
||
redhat openstack 15 |