Cross-Site Scripting Vulnerability in RabbitMQ Messaging Broker
CVE-2025-30219
6.1MEDIUM
What is CVE-2025-30219?
A vulnerability in RabbitMQ allows attackers to exploit the management UI by modifying the virtual host name stored on disk. Attackers can craft a failing virtual host that triggers the display of an error message containing unescaped input in the management interface. This can lead to arbitrary JavaScript execution within the browsers of users accessing the management UI. Versions prior to 4.0.3 of RabbitMQ and Tanzu RabbitMQ 4.0.3 and 3.13.8 contain this security flaw, which has been addressed in subsequent releases.
Affected Version(s)
rabbitmq-server < 4.0.3
