CyberRota Analysis
AI-GeneratedThe RabbitMQ management UI prior to version 4.2.5 is vulnerable due to improper escaping of the x-internal-purpose queue or exchange argument in HTML title attributes, which can lead to cross-site scripting (XSS) attacks. This vulnerability allows an authenticated user to execute JavaScript in another user's browser, potentially compromising sensitive information. Organizations using affected versions of RabbitMQ should prioritize updating to version 4.2.5 to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
RabbitMQ is a messaging and streaming broker. Prior to 4.2.5, the RabbitMQ management UI renders the x-internal-purpose queue or exchange argument into an HTML title attribute without proper escaping on the Queues and Exchanges pages, allowing a user with permission to declare a queue or exchange to execute JavaScript in another user's browser. This issue is fixed in version 4.2.5.
Related CVEs
Other vulnerabilities affecting the same vendor(s)