Cross-Site Scripting Vulnerability in RabbitMQ Management Plugin
CVE-2014-9649
Currently unrated
Summary
The RabbitMQ Management Plugin exhibits a cross-site scripting vulnerability due to improper handling of path info in error messages. This flaw, present in versions 2.1.0 through 3.4.x prior to 3.4.1, allows remote attackers to inject and execute arbitrary web scripts or HTML. The vulnerability exposes web applications using this plugin to potential security risks and data breaches. It is crucial for users to upgrade to the latest version to mitigate the risk.
References
Timeline
Vulnerability published
Vulnerability Reserved