CVE-2021-32719 log
| Source |
|
| Severity | Low |
| Remote | Yes |
| Type | Cross-site scripting |
| Description | In rabbitmq-server prior to version 3.8.18, when a federation link was displayed in the RabbitMQ management UI via the rabbitmq_federation_management plugin, its consumer tag was rendered without proper <script> tag sanitization, potentially allowing for JavaScript code execution in the context of the page. |
| Group | Package | Affected | Fixed | Severity | Status | Ticket |
|---|---|---|---|---|---|---|
| AVG-2109 | rabbitmq | 3.8.16-1 | 3.8.19-1 | Low | Fixed |
| Date | Advisory | Group | Package | Severity | Type |
|---|---|---|---|---|---|
| 06 Jul 2021 | ASA-202107-17 | AVG-2109 | rabbitmq | Low | cross-site scripting |
| Notes |
|---|
Workaround ========== As a workaround, disable the rabbitmq_management plugin and use CLI tools instead. |