CVE-2019-11281 - CVE House
Back to Database
Status published Low CVE-2019-11281

RabbitMQ XSS attack

Vulnerability Description

Pivotal RabbitMQ, versions prior to v3.7.18, and RabbitMQ for PCF, versions 1.15.x prior to 1.15.13, versions 1.16.x prior to 1.16.6, and versions 1.17.x prior to 1.17.3, contain two components, the virtual host limits page, and the federation management UI, which do not properly sanitize user input. A remote authenticated malicious user with administrative access could craft a cross site scripting attack that would gain access to virtual hosts and policy management information.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-11281

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

RabbitMQ, RabbitMQ for PCF
Vulnerable Versions:
prior to v3.7.18, 1.15.x prior to 1.15.13, 11.16.x prior to 1.16.6, 1.17.x prior to 1.17.3

Timeline

Official Publish: October 16th, 2019
Last Modified: September 16th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N

Weaknesses (CWE)