First published: Tue Jun 13 2017(Updated: )
An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to 1.6.18, and 1.7.x versions prior to 1.7.15. Several forms in the RabbitMQ management UI are vulnerable to XSS attacks.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pivotal Software Bosh CLI | =3.5.4 | |
Pivotal Software Bosh CLI | =3.5.5 | |
Pivotal Software Bosh CLI | =3.5.7 | |
Pivotal Software Bosh CLI | =3.6.0 | |
Pivotal Software Bosh CLI | =3.6.1 | |
Pivotal Software Bosh CLI | =3.6.2 | |
Pivotal Software Bosh CLI | =3.6.3 | |
Pivotal Software Bosh CLI | =3.6.4 | |
Pivotal Software Bosh CLI | =3.6.5 | |
Pivotal Software Bosh CLI | =3.6.6 | |
RabbitMQ (Pivotal Software) | =3.4.0 | |
RabbitMQ (Pivotal Software) | =3.4.1 | |
RabbitMQ (Pivotal Software) | =3.4.2 | |
RabbitMQ (Pivotal Software) | =3.4.3 | |
RabbitMQ (Pivotal Software) | =3.4.4 | |
RabbitMQ (Pivotal Software) | =3.5.0 | |
RabbitMQ (Pivotal Software) | =3.5.1 | |
RabbitMQ (Pivotal Software) | =3.5.2 | |
RabbitMQ (Pivotal Software) | =3.5.3 | |
RabbitMQ (Pivotal Software) | =3.5.6 | |
RabbitMQ (Pivotal Software) | =3.6.7 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.5.0 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.5.1 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.5.2 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.5.3 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.5.4 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.5.5 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.5.6 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.5.7 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.5.8 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.5.9 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.5.10 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.5.11 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.5.12 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.5.13 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.5.14 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.5.15 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.5.17 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.5.18 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.5.19 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.6.0 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.6.1 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.6.2 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.6.3 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.6.4 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.6.5 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.6.6 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.6.7 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.6.8 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.6.9 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.6.10 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.6.12 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.6.13 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.6.14 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.6.15 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.6.16 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.7.0 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.7.2 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.7.3 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.7.4 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.7.5 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.7.6 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.7.7 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.7.8 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.7.9 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.7.10 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.7.13 | |
Pivotal RabbitMQ for Pivotal Cloud Foundry | =1.7.14 | |
Debian Linux | =9.0 | |
RabbitMQ Server | =3.4.0 | |
RabbitMQ Server | =3.4.1 | |
RabbitMQ Server | =3.4.2 | |
RabbitMQ Server | =3.4.3 | |
RabbitMQ Server | =3.4.4 | |
RabbitMQ Server | =3.5.0 | |
RabbitMQ Server | =3.5.1 | |
RabbitMQ Server | =3.5.2 | |
RabbitMQ Server | =3.5.3 | |
RabbitMQ Server | =3.5.6 | |
RabbitMQ Server | =3.6.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-4967 is considered to have a medium severity level.
To fix CVE-2017-4967, upgrade RabbitMQ to the latest version that is not affected, such as versions 3.6.9 or later.
CVE-2017-4967 affects all RabbitMQ versions in the 3.4.x, 3.5.x, and 3.6.x series prior to 3.6.9.
Yes, all versions of RabbitMQ for Pivotal Cloud Foundry prior to 1.6.18 and all 1.7.x versions prior to 1.7.15 are affected by CVE-2017-4967.
No official workarounds are recommended for CVE-2017-4967, and upgrading to a patched version is the best course of action.