Cross-Site Scripting Vulnerability in RabbitMQ Management Plugin
CVE-2014-9649

Currently unrated

Key Information:

Vendor
Vmware
Status
Vendor
CVE Published:
27 January 2015

Summary

The RabbitMQ Management Plugin exhibits a cross-site scripting vulnerability due to improper handling of path info in error messages. This flaw, present in versions 2.1.0 through 3.4.x prior to 3.4.1, allows remote attackers to inject and execute arbitrary web scripts or HTML. The vulnerability exposes web applications using this plugin to potential security risks and data breaches. It is crucial for users to upgrade to the latest version to mitigate the risk.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.