CVE-2019-11291: RabbitMQ XSS attack via federation and shovel endpoints
Pivotal RabbitMQ, 3.7 versions prior to v3.7.20 and 3.8 version prior to v3.8.1, and RabbitMQ for PCF, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain two endpoints, federation and shovel, which do not properly sanitize user input. A remote authenticated malicious user with administrative access could craft a cross site scripting attack via the vhost or node name fields that could grant access to virtual hosts and policy management information.
Other sources
Two endpoints, federation and shovel, do not properly sanitize user input. A remote authenticated malicious user with administrative access could craft a cross site scripting attack via the vhost or node name fields that could grant access to virtual hosts and policy management information.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-11291?
The severity of CVE-2019-11291 is medium with a CVSS score of 4.8.
Which versions of Pivotal RabbitMQ are affected by CVE-2019-11291?
Pivotal RabbitMQ versions prior to v3.7.20 and 3.8 version prior to v3.8.1 are affected.
Which versions of RabbitMQ for PCF are affected by CVE-2019-11291?
RabbitMQ for PCF, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4 are affected.
What is the vulnerability description of CVE-2019-11291?
CVE-2019-11291 allows a remote authenticated malicious user to exploit two endpoints (federation and shovel) that do not properly sanitize user input.
Is there a fix available for CVE-2019-11291?
Yes, the fix for CVE-2019-11291 is available in Pivotal RabbitMQ version v3.7.20, 3.8 version v3.8.1, RabbitMQ for PCF version 1.16.7, and 1.17.4.