CVE-2014-9494: Medium severity Pivotal Software RabbitMQ vulnerability
Published Jan 20, 2015
·Updated
RabbitMQ before 3.4.0 allows remote attackers to bypass the loopbackusers restriction via a crafted X-Forwareded-For header.
Affected Software
1 affected component
Pivotal Software RabbitMQ<=3.3.5
Event History
Jan 20, 2015
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-9494?
CVE-2014-9494 is considered a medium severity vulnerability that allows remote attackers to bypass security restrictions.
2
How do I fix CVE-2014-9494?
To fix CVE-2014-9494, upgrade RabbitMQ to version 3.4.0 or later.
3
What versions of RabbitMQ are affected by CVE-2014-9494?
CVE-2014-9494 affects RabbitMQ versions prior to 3.4.0, including all versions up to 3.3.5.
4
What impact does CVE-2014-9494 have on system security?
CVE-2014-9494 allows attackers to bypass the loopback_users restriction, potentially leading to unauthorized access.
5
Is a patch available for CVE-2014-9494?
Yes, a patch is available by upgrading to RabbitMQ version 3.4.0 or later.