CVE-2019-11291 - CVE House
Back to Database
Status published Low CVE-2019-11291

RabbitMQ XSS attack via federation and shovel endpoints

Vulnerability Description

Pivotal RabbitMQ, 3.7 versions prior to v3.7.20 and 3.8 version prior to v3.8.1, and RabbitMQ for PCF, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain two endpoints, federation and shovel, which do not properly sanitize user input. A remote authenticated malicious user with administrative access could craft a cross site scripting attack via the vhost or node name fields that could grant access to virtual hosts and policy management information.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-11291

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

RabbitMQ, RabbitMQ for Pivotal Platform
Vulnerable Versions:
3.8, 3.7, 1.17, 1.16

Timeline

Official Publish: November 22nd, 2019
Last Modified: September 17th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N

Weaknesses (CWE)