CVE-2021-32719 log

Source
Severity Low
Remote Yes
Type Cross-site scripting
Description
In rabbitmq-server prior to version 3.8.18, when a federation link was displayed in the RabbitMQ management UI via the rabbitmq_federation_management plugin, its consumer tag was rendered without proper <script> tag sanitization, potentially allowing for JavaScript code execution in the context of the page.
Group Package Affected Fixed Severity Status Ticket
AVG-2109 rabbitmq 3.8.16-1 3.8.19-1 Low Fixed
Date Advisory Group Package Severity Type
06 Jul 2021 ASA-202107-17 AVG-2109 rabbitmq Low cross-site scripting
References
https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-5452-hxj4-773x
https://github.com/rabbitmq/rabbitmq-server/pull/3122
https://github.com/rabbitmq/rabbitmq-server/commit/08beb82e9ab8923ded88ece2800cd80971e2bd05
Notes
Workaround
==========

As a workaround, disable the rabbitmq_management plugin and use CLI tools instead.