CVE Database
/

CVE-2019-11291

Back to search

CVE-2019-11291

Published: Nov 22, 2019

Modified: Sep 17, 2024

PUBLISHED

CVSS v3.0

3.1

LOW

Description

Pivotal RabbitMQ, 3.7 versions prior to v3.7.20 and 3.8 version prior to v3.8.1, and RabbitMQ for PCF, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain two endpoints, federation and shovel, which do not properly sanitize user input. A remote authenticated malicious user with administrative access could craft a cross site scripting attack via the vhost or node name fields that could grant access to virtual hosts and policy management information.

VendorProductVersions

Pivotal

RabbitMQ

affected
3.8 - < v3.8.1
affected
3.7 - < v3.7.20

Pivotal

RabbitMQ for Pivotal Platform

affected
1.17 - < 1.17.4
affected
1.16 - < 1.16.7

Weaknesses (CWE)

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N

Attack Vector

Network

Attack Complexity

High

Privileges Required

High

User Interaction

Required

Scope

Unchanged

Confidentiality

Low

Integrity

Low

Availability

None

References

RHSA-2020:0553
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now