<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – RabbitMQ</title>
  <link>https://cvedaily.com/pages/tags/rabbitmq.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/rabbitmq.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – RabbitMQ</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:34 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-9844 – Use of default credentials vulnerability in Roche Diagnostics navify Digital Pat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9844</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9844</guid>
    <pubDate>Tue, 02 Jun 2026 14:17:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9844</strong></p>
  <p>Use of default credentials vulnerability in Roche Diagnostics navify Digital Pathology (RabbitMQ Management interface modules) allows Default Usernames and Passwords. This issue affects navify Digital Pathology: from 2.0.0 before 2.4.1.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1392</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9844">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44839 – RabbitMQ is a messaging and streaming broker. From 3.7.0 to before 4.1.2 and 4.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44839</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44839</guid>
    <pubDate>Wed, 27 May 2026 15:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44839</strong></p>
  <p>RabbitMQ is a messaging and streaming broker. From 3.7.0 to before 4.1.2 and 4.0.13,  This vulnerability is fixed in 4.1.2 and 4.0.13.</p>
  <p><strong>CVSS:</strong> 5.6 · <strong>CWE:</strong> CWE-80</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44839">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-44838 – RabbitMQ is a messaging and streaming broker. From 4.2.0 to before 4.2.4, Rabbit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44838</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44838</guid>
    <pubDate>Wed, 27 May 2026 15:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-44838</strong></p>
  <p>RabbitMQ is a messaging and streaming broker. From 4.2.0 to before 4.2.4, RabbitMQ's MQTT plugin allows for topic-level authorization using regular expressions with variable substitution. Administrators can create patterns such as ^{client_id}-sensors$ to restrict user access to topics that include their client ID. However, the client_id is provided by the user in the MQTT CONNECT packet and is i…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44838">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25112 – A high-severity vulnerability in the deployment of Genetec RabbitMQ that allows ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25112</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25112</guid>
    <pubDate>Tue, 26 May 2026 16:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25112</strong></p>
  <p>A high-severity vulnerability in the deployment of Genetec RabbitMQ that allows a privilege escalation attack.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25112">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9133 – Active debug code exists in the ARN resolver of amazon-mq rabbitmq-aws before ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9133</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9133</guid>
    <pubDate>Wed, 20 May 2026 20:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9133</strong></p>
  <p>Active debug code exists in the ARN resolver of amazon-mq rabbitmq-aws before version 0.2.1. A debug ARN scheme (arn:aws-debug:file) accepted by the PUT /api/aws/arn/validate validation endpoint might allow remote authenticated users to perform arbitrary file reads on any file accessible to the RabbitMQ process.     To remediate this issue, customers should upgrade to version 0.2.1 of rabbitmq-aw…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-489</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9133">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-40971 – When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40971</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40971</guid>
    <pubDate>Mon, 27 Apr 2026 23:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-40971</strong></p>
  <p>When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification when connecting to the RabbitMQ broker.  Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14) per vendor advisory.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40971">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-50200 – RabbitMQ is a messaging and streaming broker. In versions 3.13.7 and prior, Rabb...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-50200</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-50200</guid>
    <pubDate>Thu, 19 Jun 2025 17:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-50200</strong></p>
  <p>RabbitMQ is a messaging and streaming broker. In versions 3.13.7 and prior, RabbitMQ is logging authorization headers in plaintext encoded in base64. When querying RabbitMQ api with HTTP/s with basic authentication it creates logs with all headers in request, including authorization headers which show base64 encoded username:password. This is easy to decode and afterwards could be used to obtain…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-50200">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-30219 – RabbitMQ is a messaging and streaming broker. Versions prior to 4.0.3 are vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30219</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30219</guid>
    <pubDate>Tue, 25 Mar 2025 23:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-30219</strong></p>
  <p>RabbitMQ is a messaging and streaming broker. Versions prior to 4.0.3 are vulnerable to a sophisticated attack that could modify virtual host name on disk and then make it unrecoverable (with other on disk file modifications) can lead to arbitrary JavaScript code execution in the browsers of management UI users. When a virtual host on a RabbitMQ node fails to start, recent versions will display a…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30219">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-27636 – Bypass/Injection vulnerability in Apache Camel components under particular condi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27636</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27636</guid>
    <pubDate>Sun, 09 Mar 2025 13:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-27636</strong></p>
  <p>Bypass/Injection vulnerability in Apache Camel components under particular conditions.  This issue affects Apache Camel: from 4.10.0 through <= 4.10.1, from 4.8.0 through <= 4.8.4, from 3.10.0 through <= 3.22.3.  Users are recommended to upgrade to version 4.10.2 for 4.10.x LTS, 4.8.5 for 4.8.x LTS and 3.22.4 for 3.x releases.    This vulnerability is present in Camel's default incoming header fi…</p>
  <p><strong>CVSS:</strong> 5.6 · <strong>CWE:</strong> CWE-178</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27636">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-24400 – Jenkins Eiffel Broadcaster Plugin 2.8.0 through 2.10.2 (both inclusive) uses the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24400</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24400</guid>
    <pubDate>Wed, 22 Jan 2025 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-24400</strong></p>
  <p>Jenkins Eiffel Broadcaster Plugin 2.8.0 through 2.10.2 (both inclusive) uses the credential ID as the cache key during signing operations, allowing attackers able to create a credential with the same ID as a legitimate one in a different credentials store to sign an event published to RabbitMQ with the legitimate credentials.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24400">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-51988 – RabbitMQ is a feature rich, multi-protocol messaging and streaming broker. In af...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51988</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51988</guid>
    <pubDate>Wed, 06 Nov 2024 20:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-51988</strong></p>
  <p>RabbitMQ is a feature rich, multi-protocol messaging and streaming broker. In affected versions queue deletion via the HTTP API was not verifying the `configure` permission of the user. Users who had all of the following: 1. Valid credentials, 2. Some permissions for the target virtual host & 3. HTTP API access. could delete queues it had no (deletion) permissions for. This issue has been address…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51988">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-28990 – SolarWinds Access Rights Manager (ARM) was found to contain a hard-coded credent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-28990</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-28990</guid>
    <pubDate>Thu, 12 Sep 2024 14:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-28990</strong></p>
  <p>SolarWinds Access Rights Manager (ARM) was found to contain a hard-coded credential authentication bypass vulnerability. If exploited, this vulnerability would allow access to the RabbitMQ management console.  We thank Trend Micro Zero Day Initiative (ZDI) for its ongoing partnership in coordinating with SolarWinds on responsible disclosure of this and other potential vulnerabilities.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-28990">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-23473 – The SolarWinds Access Rights Manager was found to contain a hard-coded credentia...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23473</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23473</guid>
    <pubDate>Tue, 14 May 2024 14:59:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-23473</strong></p>
  <p>The SolarWinds Access Rights Manager was found to contain a hard-coded credential authentication bypass vulnerability. If exploited, this vulnerability allows access to the RabbitMQ management console.   We thank Trend Micro Zero Day Initiative (ZDI) for its ongoing partnership in coordinating with SolarWinds on responsible disclosure of this and other potential vulnerabilities.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23473">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-25649 – In Delinea PAM Secret Server 11.4, it is possible for an attacker (with Administ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-25649</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-25649</guid>
    <pubDate>Thu, 14 Mar 2024 03:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-25649</strong></p>
  <p>In Delinea PAM Secret Server 11.4, it is possible for an attacker (with Administrator access to the Secret Server machine) to read the following data from a memory dump: the decrypted master key, database credentials (when SQL Server Authentication is enabled), the encryption key of RabbitMQ queue messages, and session cookies.</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-316</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-25649">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-25650 – Insecure key exchange between Delinea PAM Secret Server 11.4 and the Distributed...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-25650</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-25650</guid>
    <pubDate>Thu, 14 Mar 2024 02:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-25650</strong></p>
  <p>Insecure key exchange between Delinea PAM Secret Server 11.4 and the Distributed Engine 8.4.3 allows a PAM administrator to obtain the Symmetric Key (used to encrypt RabbitMQ messages) via crafted payloads to the /pre-authenticate, /authenticate, and /execute-and-respond REST API endpoints. This makes it possible for a PAM administrator to impersonate the Engine and exfiltrate sensitive informati…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-319</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-25650">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-1156 – Incorrect directory permissions for the shared NI RabbitMQ service may allow a l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-1156</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-1156</guid>
    <pubDate>Tue, 20 Feb 2024 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-1156</strong></p>
  <p>Incorrect directory permissions for the shared NI RabbitMQ service may allow a local authenticated user to read RabbitMQ configuration information and potentially enable escalation of privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1156">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-46120 – The RabbitMQ Java client library allows Java and JVM-based applications to conne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46120</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46120</guid>
    <pubDate>Wed, 25 Oct 2023 18:17:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-46120</strong></p>
  <p>The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. `maxBodyLebgth` was not used when receiving Message objects.  Attackers could send a very large Message causing a memory overflow and triggering an OOM Error. Users of RabbitMQ may suffer from  DoS attacks from RabbitMQ Java client which will ultimately exhaust the memory of the…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46120">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-46118 – RabbitMQ is a multi-protocol messaging and streaming broker. HTTP API did not en...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46118</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46118</guid>
    <pubDate>Wed, 25 Oct 2023 18:17:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-46118</strong></p>
  <p>RabbitMQ is a multi-protocol messaging and streaming broker. HTTP API did not enforce an HTTP request body limit, making it vulnerable for denial of service (DoS) attacks with very large messages. An authenticated user with sufficient credentials can publish a very large messages over the HTTP API and cause target node to be terminated by an "out-of-memory killer"-like mechanism. This vulnerabili…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46118">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-34050 – In spring AMQP versions 1.0.0 to
2.4.16 and 3.0.0 to 3.0.9 , allowed list patter...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-34050</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-34050</guid>
    <pubDate>Thu, 19 Oct 2023 08:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-34050</strong></p>
  <p>In spring AMQP versions 1.0.0 to 2.4.16 and 3.0.0 to 3.0.9 , allowed list patterns for deserializable class names were added to Spring AMQP, allowing users to lock down deserialization of data in messages from untrusted sources; however by default, when no allowed list was provided, all classes could be deserialized.    Specifically, an application is vulnerable if        *  the      SimpleMessag…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-34050">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-40256 – A vulnerability was discovered in Veritas NetBackup Snapshot Manager before 10.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40256</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40256</guid>
    <pubDate>Fri, 11 Aug 2023 05:15:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-40256</strong></p>
  <p>A vulnerability was discovered in Veritas NetBackup Snapshot Manager before 10.2.0.1 that allowed untrusted clients to interact with the RabbitMQ service. This was caused by improper validation of the client certificate due to misconfiguration of the RabbitMQ service. Exploiting this impacts the confidentiality and integrity of messages controlling the backup and restore jobs, and could result in…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40256">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-26512 – CWE-502 Deserialization of Untrusted Data at the rabbitmq-connector plugin modul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-26512</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-26512</guid>
    <pubDate>Mon, 17 Jul 2023 08:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-26512</strong></p>
  <p>CWE-502 Deserialization of Untrusted Data at the rabbitmq-connector plugin module in Apache EventMesh (incubating) V1.7.0\V1.8.0 on windows\linux\mac os e.g. platforms allows attackers to send controlled message and   remote code execute via rabbitmq messages. Users can use the code under the master branch in project repo to fix this issue, we will release the new version as soon as possible.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26512">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-35789 – An issue was discovered in the C AMQP client library (aka rabbitmq-c) through 0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-35789</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-35789</guid>
    <pubDate>Fri, 16 Jun 2023 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-35789</strong></p>
  <p>An issue was discovered in the C AMQP client library (aka rabbitmq-c) through 0.13.0 for RabbitMQ. Credentials can only be entered on the command line (e.g., for amqp-publish or amqp-consume) and are thus visible to local attackers by listing a process and its arguments.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-35789">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-24568 – Dell NetWorker, contains an Improper Validation of Certificate with Host Mismatc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-24568</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-24568</guid>
    <pubDate>Tue, 30 May 2023 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-24568</strong></p>
  <p>Dell NetWorker, contains an Improper Validation of Certificate with Host Mismatch vulnerability in Rabbitmq port which could disallow replacing CA signed certificates.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-297</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24568">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-24567 – Dell NetWorker versions 19.5 and earlier contain 'RabbitMQ' version disclosure v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-24567</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-24567</guid>
    <pubDate>Wed, 01 Mar 2023 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-24567</strong></p>
  <p>Dell NetWorker versions 19.5 and earlier contain 'RabbitMQ' version disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and may launch target-specific attacks.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24567">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-24448 – A missing permission check in Jenkins RabbitMQ Consumer Plugin 2.8 and earlier a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-24448</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-24448</guid>
    <pubDate>Thu, 26 Jan 2023 21:18:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-24448</strong></p>
  <p>A missing permission check in Jenkins RabbitMQ Consumer Plugin 2.8 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified AMQP(S) URL using attacker-specified username and password.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24448">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-24447 – A cross-site request forgery (CSRF) vulnerability in Jenkins RabbitMQ Consumer P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-24447</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-24447</guid>
    <pubDate>Thu, 26 Jan 2023 21:18:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-24447</strong></p>
  <p>A cross-site request forgery (CSRF) vulnerability in Jenkins RabbitMQ Consumer Plugin 2.8 and earlier allows attackers to connect to an attacker-specified AMQP(S) URL using attacker-specified username and password.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24447">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-31008 – RabbitMQ is a multi-protocol messaging and streaming broker. In affected version...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31008</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31008</guid>
    <pubDate>Thu, 06 Oct 2022 18:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-31008</strong></p>
  <p>RabbitMQ is a multi-protocol messaging and streaming broker. In affected versions the shovel and federation plugins perform URI obfuscation in their worker (link) state. The encryption key used to encrypt the URI was seeded with a predictable secret. This means that in case of certain exceptions related to Shovel and Federation plugins, reasonably easily deobfuscatable data could appear in the no…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-330</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31008">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-38665 – Jenkins CollabNet Plugins Plugin 2.0.8 and earlier stores a RabbitMQ password un...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-38665</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-38665</guid>
    <pubDate>Tue, 23 Aug 2022 17:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-38665</strong></p>
  <p>Jenkins CollabNet Plugins Plugin 2.0.8 and earlier stores a RabbitMQ password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-38665">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2022-29082 – Dell EMC NetWorker versions 19.1.x, 19.1.0.x, 19.1.1.x, 19.2.x, 19.2.0.x, 19.2.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-29082</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-29082</guid>
    <pubDate>Thu, 26 May 2022 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2022-29082</strong></p>
  <p>Dell EMC NetWorker versions 19.1.x, 19.1.0.x, 19.1.1.x, 19.2.x, 19.2.0.x, 19.2.1.x 19.3.x, 19.3.0.x, 19.4.x, 19.4.0.x, 19.5.x,19.5.0.x, 19.6 and 19.6.0.1 and 19.6.0.2 contain an Improper Validation of Certificate with Host Mismatch vulnerability in Rabbitmq port 5671 which could allow remote attackers to spoof certificates.</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-297</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-29082">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-43799 – Zulip is an open-source team collaboration tool. Zulip Server installs RabbitMQ ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-43799</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-43799</guid>
    <pubDate>Tue, 25 Jan 2022 21:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-43799</strong></p>
  <p>Zulip is an open-source team collaboration tool. Zulip Server installs RabbitMQ for internal message passing. In versions of Zulip Server prior to 4.9, the initial installation (until first reboot, or restart of RabbitMQ) does not successfully limit the default ports which RabbitMQ opens; this includes port 25672, the RabbitMQ distribution port, which is used as a management port. RabbitMQ's defa…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-338</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-43799">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-23207 – An attacker with physical access to the host can extract the secrets from the re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-23207</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-23207</guid>
    <pubDate>Fri, 21 Jan 2022 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-23207</strong></p>
  <p>An attacker with physical access to the host can extract the secrets from the registry and create valid JWT tokens for the Fresenius Kabi Vigilant MasterMed version 2.0.1.3 application and impersonate arbitrary users. An attacker could manipulate RabbitMQ queues and messages by impersonating users.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-256</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-23207">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-35227 – The HTTP interface was enabled for RabbitMQ Plugin in ARM 2020.2.6 and the abili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-35227</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-35227</guid>
    <pubDate>Thu, 21 Oct 2021 18:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-35227</strong></p>
  <p>The HTTP interface was enabled for RabbitMQ Plugin in ARM 2020.2.6 and the ability to configure HTTPS was not available.</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-35227">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-0279 – Juniper Networks Contrail Cloud (CC) releases prior to 13.6.0 have RabbitMQ serv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-0279</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-0279</guid>
    <pubDate>Thu, 15 Jul 2021 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-0279</strong></p>
  <p>Juniper Networks Contrail Cloud (CC) releases prior to 13.6.0 have RabbitMQ service enabled by default with hardcoded credentials. The messaging services of RabbitMQ are used when coordinating operations and status information among Contrail services. An attacker with access to an administrative service for RabbitMQ (e.g. GUI), can use these hardcoded credentials to cause a Denial of Service (DoS…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-0279">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2021-32719 – RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to versi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32719</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32719</guid>
    <pubDate>Mon, 28 Jun 2021 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2021-32719</strong></p>
  <p>RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.18, when a federation link was displayed in the RabbitMQ management UI via the `rabbitmq_federation_management` plugin, its consumer tag was rendered without proper <script> tag sanitization. This potentially allows for JavaScript code execution in the context of the page. The user must be signed in and have el…</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-80</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32719">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2021-32718 – RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to versi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32718</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32718</guid>
    <pubDate>Mon, 28 Jun 2021 15:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2021-32718</strong></p>
  <p>RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.17, a new user being added via management UI could lead to the user's bane being rendered in a confirmation message without proper `<script>` tag sanitization, potentially allowing for JavaScript code execution in the context of the page. In order for this to occur, the user must be signed in and have elevated…</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-80</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32718">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22116 – RabbitMQ all versions prior to 3.8.16 are prone to a denial of service vulnerabi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22116</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22116</guid>
    <pubDate>Tue, 08 Jun 2021 12:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22116</strong></p>
  <p>RabbitMQ all versions prior to 3.8.16 are prone to a denial of service vulnerability due to improper input validation in AMQP 1.0 client connection endpoint. A malicious user can exploit the vulnerability by sending malicious AMQP messages to the target RabbitMQ instance having the AMQP 1.0 plugin enabled.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22116">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22117 – RabbitMQ installers on Windows prior to version 3.8.16 do not harden plugin dire...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22117</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22117</guid>
    <pubDate>Tue, 18 May 2021 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22117</strong></p>
  <p>RabbitMQ installers on Windows prior to version 3.8.16 do not harden plugin directory permissions, potentially allowing attackers with sufficient local filesystem permissions to add arbitrary plugins.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22117">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-36282 – JMS Client for RabbitMQ 1.x before 1.15.2 and 2.x before 2.2.0 is vulnerable to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-36282</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-36282</guid>
    <pubDate>Fri, 12 Mar 2021 01:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-36282</strong></p>
  <p>JMS Client for RabbitMQ 1.x before 1.15.2 and 2.x before 2.2.0 is vulnerable to unsafe deserialization that can result in code execution via crafted StreamMessage data.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-36282">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-35196 – The official rabbitmq docker images before 3.7.13-beta.1-management-alpine (Alpi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-35196</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-35196</guid>
    <pubDate>Thu, 17 Dec 2020 02:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-35196</strong></p>
  <p>The official rabbitmq docker images before 3.7.13-beta.1-management-alpine (Alpine specific) contain a blank password for a root user. System using the rabbitmq docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-35196">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-5419 – RabbitMQ versions 3.8.x prior to 3.8.7 are prone to a Windows-specific binary pl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-5419</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-5419</guid>
    <pubDate>Mon, 31 Aug 2020 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-5419</strong></p>
  <p>RabbitMQ versions 3.8.x prior to 3.8.7 are prone to a Windows-specific binary planting security vulnerability that allows for arbitrary code execution. An attacker with write privileges to the RabbitMQ installation directory and local access on Windows could carry out a local binary hijacking (planting) attack and execute arbitrary code.</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-5419">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-11982 – An issue was found in Apache Airflow versions 1.10.10 and below. When using Cele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-11982</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-11982</guid>
    <pubDate>Fri, 17 Jul 2020 00:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-11982</strong></p>
  <p>An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attack can connect to the broker (Redis, RabbitMQ) directly, it was possible to insert a malicious payload directly to the broker which could lead to a deserialization attack (and thus remote code execution) on the Worker.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11982">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-11981 – An issue was found in Apache Airflow versions 1.10.10 and below. When using Cele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-11981</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-11981</guid>
    <pubDate>Fri, 17 Jul 2020 00:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-11981</strong></p>
  <p>An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attacker can connect to the broker (Redis, RabbitMQ) directly, it is possible to inject commands, resulting in the celery worker running arbitrary commands.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11981">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-11972 – Apache Camel RabbitMQ enables Java deserialization by default. Apache Camel 2.22...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-11972</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-11972</guid>
    <pubDate>Thu, 14 May 2020 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-11972</strong></p>
  <p>Apache Camel RabbitMQ enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11972">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-2032 – A vulnerability exists in the Aruba AirWave Management Platform 8.x prior to 8.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-2032</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-2032</guid>
    <pubDate>Fri, 31 Jan 2020 20:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-2032</strong></p>
  <p>A vulnerability exists in the Aruba AirWave Management Platform 8.x prior to 8.2 in the management interface of an underlying system component called RabbitMQ, which could let a malicious user obtain sensitive information. This interface listens on TCP port 15672 and 55672</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-2032">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-19342 – A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19342</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19342</guid>
    <pubDate>Thu, 19 Dec 2019 21:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-19342</strong></p>
  <p>A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.4, when /websocket is requested and the password contains the '#' character. This request would cause a socket error in RabbitMQ when parsing the password and an HTTP error code 500 and partial password disclose will occur in plaintext. An attacker could easily guess some predictable passwords or brute force the p…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-209</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19342">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-19340 – A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19340</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19340</guid>
    <pubDate>Thu, 19 Dec 2019 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-19340</strong></p>
  <p>A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.3, where enabling RabbitMQ manager by setting it with '-e rabbitmq_enable_manager=true' exposes the RabbitMQ management interface publicly, as expected. If the default admin user is still active, an attacker could guess the password and gain access to the system.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-1188</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19340">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-18609 – An issue was discovered in amqp_handle_input in amqp_connection.c in rabbitmq-c ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-18609</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-18609</guid>
    <pubDate>Sun, 01 Dec 2019 22:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-18609</strong></p>
  <p>An issue was discovered in amqp_handle_input in amqp_connection.c in rabbitmq-c 0.9.0. There is an integer overflow that leads to heap memory corruption in the handling of CONNECTION_STATE_HEADER. A rogue server could return a malicious frame header that leads to a smaller target_size value than needed. This condition is then carried on to a memcpy function that copies too much data into a heap b…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-18609">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-11287 – Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and R...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-11287</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-11287</guid>
    <pubDate>Sat, 23 Nov 2019 00:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-11287</strong></p>
  <p>Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is vulnerable to a denial of service attack. The "X-Reason" HTTP Header can be leveraged to insert a malicious Erlang format string that will expand and consume the heap, resulting in…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-11287">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-11291 – Pivotal RabbitMQ, 3.7 versions prior to v3.7.20 and 3.8 version prior to v3.8.1,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-11291</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-11291</guid>
    <pubDate>Fri, 22 Nov 2019 23:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-11291</strong></p>
  <p>Pivotal RabbitMQ, 3.7 versions prior to v3.7.20 and 3.8 version prior to v3.8.1, and RabbitMQ for PCF, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain two endpoints, federation and shovel, which do not properly sanitize user input. A remote authenticated malicious user with administrative access could craft a cross site scripting attack via the vhost or node name fiel…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-11291">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-11281 – Pivotal RabbitMQ, versions prior to v3.7.18, and RabbitMQ for PCF, versions 1.15...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-11281</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-11281</guid>
    <pubDate>Wed, 16 Oct 2019 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-11281</strong></p>
  <p>Pivotal RabbitMQ, versions prior to v3.7.18, and RabbitMQ for PCF, versions 1.15.x prior to 1.15.13, versions 1.16.x prior to 1.16.6, and versions 1.17.x prior to 1.17.3, contain two components, the virtual host limits page, and the federation management UI, which do not properly sanitize user input. A remote authenticated malicious user with administrative access could craft a cross site scripti…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-11281">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-9546 – SolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation thr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-9546</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-9546</guid>
    <pubDate>Fri, 01 Mar 2019 22:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-9546</strong></p>
  <p>SolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation through the RabbitMQ service.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-9546">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-16879 – Ansible Tower before version 3.3.3 does not set a secure channel as it is using ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-16879</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-16879</guid>
    <pubDate>Thu, 03 Jan 2019 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-16879</strong></p>
  <p>Ansible Tower before version 3.3.3 does not set a secure channel as it is using the default insecure configuration channel settings for messaging celery workers from RabbitMQ. This could lead in data leak of sensitive information such as passwords as well as denial of service attacks by deleting projects or inventory files.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-311</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-16879">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1279 – Pivotal RabbitMQ for PCF, all versions, uses a deterministically generated cooki...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1279</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1279</guid>
    <pubDate>Mon, 10 Dec 2018 19:29:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1279</strong></p>
  <p>Pivotal RabbitMQ for PCF, all versions, uses a deterministically generated cookie that is shared between all machines when configured in a multi-tenant cluster. A remote attacker who can gain information about the network topology can guess this cookie and, if they have access to the right ports on any server in the MQ cluster can use this cookie to gain full control over the entire cluster.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-330</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1279">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-14620 – The OpenStack RabbitMQ container image insecurely retrieves the rabbitmq_cluster...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-14620</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-14620</guid>
    <pubDate>Mon, 10 Sep 2018 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-14620</strong></p>
  <p>The OpenStack RabbitMQ container image insecurely retrieves the rabbitmq_clusterer component over HTTP during the build stage. This could potentially allow an attacker to serve malicious code to the image builder and install in the resultant container image. Version of openstack-rabbitmq-container and openstack-containers as shipped with Red Hat Openstack 12, 13, 14 are believed to be vulnerable.</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-494</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-14620">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2017-4967 – An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4967</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4967</guid>
    <pubDate>Tue, 13 Jun 2017 06:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2017-4967</strong></p>
  <p>An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to 1.6.18, and 1.7.x versions prior to 1.7.15. Several forms in the RabbitMQ management UI are vulnerable to XSS attacks.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4967">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-4966 – An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4966</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4966</guid>
    <pubDate>Tue, 13 Jun 2017 06:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-4966</strong></p>
  <p>An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to 1.6.18, and 1.7.x versions prior to 1.7.15. RabbitMQ management UI stores signed-in user credentials in a browser's local storage without expiration, making it possible to retrieve th…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4966">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2017-4965 – An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4965</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4965</guid>
    <pubDate>Tue, 13 Jun 2017 06:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2017-4965</strong></p>
  <p>An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to 1.6.18, and 1.7.x versions prior to 1.7.15. Several forms in the RabbitMQ management UI are vulnerable to XSS attacks.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4965">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-9877 – An issue was discovered in Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before 3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9877</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9877</guid>
    <pubDate>Thu, 29 Dec 2016 09:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-9877</strong></p>
  <p>An issue was discovered in Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before 3.6.6 and RabbitMQ for PCF 1.5.x before 1.5.20, 1.6.x before 1.6.12, and 1.7.x before 1.7.7. MQTT (MQ Telemetry Transport) connection authentication with a username/password pair succeeds if an existing username is provided but the password is omitted from the connection request. Connections that use TLS with a client-p…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9877">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-8786 – The Management plugin in RabbitMQ before 3.6.1 allows remote authenticated users...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-8786</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-8786</guid>
    <pubDate>Fri, 09 Dec 2016 20:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-8786</strong></p>
  <p>The Management plugin in RabbitMQ before 3.6.1 allows remote authenticated users with certain privileges to cause a denial of service (resource consumption) via the (1) lengths_age or (2) lengths_incr parameter.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-8786">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-0929 – The metrics-collection component in RabbitMQ for Pivotal Cloud Foundry (PCF) 1.6...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-0929</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-0929</guid>
    <pubDate>Sun, 18 Sep 2016 02:59:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-0929</strong></p>
  <p>The metrics-collection component in RabbitMQ for Pivotal Cloud Foundry (PCF) 1.6.x before 1.6.4 logs command lines of failed commands, which might allow context-dependent attackers to obtain sensitive information by reading the log data, as demonstrated by a syslog message that contains credentials from a command line.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-0929">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-5329 – The TripleO Heat templates (tripleo-heat-templates), as used in Red Hat Enterpri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-5329</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-5329</guid>
    <pubDate>Mon, 11 Apr 2016 21:59:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-5329</strong></p>
  <p>The TripleO Heat templates (tripleo-heat-templates), as used in Red Hat Enterprise Linux OpenStack Platform 7.0, do not properly use the configured RabbitMQ credentials, which makes it easier for remote attackers to obtain access to services in deployed overclouds by leveraging knowledge of the default credentials.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-5329">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2015-6858 – HP Insight Control server provisioning before 7.5.0 RabbitMQ allows remote attac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-6858</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-6858</guid>
    <pubDate>Tue, 05 Jan 2016 11:59:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2015-6858</strong></p>
  <p>HP Insight Control server provisioning before 7.5.0 RabbitMQ allows remote attackers to obtain sensitive information via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-6858">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2014-9568 – puppetlabs-rabbitmq 3.0 through 4.1 stores the RabbitMQ Erlang cookie value in t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-9568</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-9568</guid>
    <pubDate>Tue, 03 Feb 2015 16:59:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2014-9568</strong></p>
  <p>puppetlabs-rabbitmq 3.0 through 4.1 stores the RabbitMQ Erlang cookie value in the facts of a node, which allows local users to obtain sensitive information as demonstrated by using Facter.</p>
  <p><strong>CVSS:</strong> 2.1 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-9568">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-9650 – CRLF injection vulnerability in the management plugin in RabbitMQ 2.1.0 through ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-9650</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-9650</guid>
    <pubDate>Tue, 27 Jan 2015 20:03:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-9650</strong></p>
  <p>CRLF injection vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the download parameter to api/definitions.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-9650">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-9649 – Cross-site scripting (XSS) vulnerability in the management plugin in RabbitMQ 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-9649</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-9649</guid>
    <pubDate>Tue, 27 Jan 2015 20:02:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-9649</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows remote attackers to inject arbitrary web script or HTML via the path info to api/, which is not properly handled in an error message.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-9649">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-9494 – RabbitMQ before 3.4.0 allows remote attackers to bypass the loopback_users restr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-9494</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-9494</guid>
    <pubDate>Tue, 20 Jan 2015 15:59:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-9494</strong></p>
  <p>RabbitMQ before 3.4.0 allows remote attackers to bypass the loopback_users restriction via a crafted X-Forwareded-For header.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-9494">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2015-0862 – Multiple cross-site scripting (XSS) vulnerabilities in the management web UI in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-0862</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-0862</guid>
    <pubDate>Sun, 18 Jan 2015 18:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2015-0862</strong></p>
  <p>Multiple cross-site scripting (XSS) vulnerabilities in the management web UI in the RabbitMQ management plugin before 3.4.3 allow remote authenticated users to inject arbitrary web script or HTML via (1) message details when a message is unqueued, such as headers or arguments; (2) policy names, which are not properly handled when viewing policies; (3) details for AMQP network clients, such as the…</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-0862">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2013-1069 – Ubuntu Metal as a Service (MaaS) 1.2 and 1.4 uses world-readable permissions for...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-1069</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-1069</guid>
    <pubDate>Mon, 17 Feb 2014 16:55:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2013-1069</strong></p>
  <p>Ubuntu Metal as a Service (MaaS) 1.2 and 1.4 uses world-readable permissions for txlongpoll.yaml, which allows local users to obtain RabbitMQ authentication credentials by reading the file.</p>
  <p><strong>CVSS:</strong> 2.1 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-1069">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
