CyberRota Analysis
AI-GeneratedRabbitMQ versions 4.2.0 to 4.2.8 and 4.3.2 are vulnerable due to improper handling of bearer tokens in OAuth bootstrap JavaScript, which can lead to cross-site scripting (XSS) attacks in the management UI. This vulnerability allows attackers to execute arbitrary JavaScript if they can control the token content, particularly when management.oauth_enabled is enabled and an access_token cookie is planted. Organizations using affected versions should prioritize updating to versions 4.2.8 or 4.3.2 to mitigate this high-severity risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.8 and 4.3.2, set_token_auth/2 inserted a bearer token from the Authorization header or access_token cookie into OAuth bootstrap JavaScript without escaping, allowing attacker-controlled token content to execute JavaScript in the management UI origin. The endpoint is exposed before authentication only when management.oauth_enabled is true, and exploitation through the cookie path additionally requires the attacker to plant an access_token cookie on the management host. This issue is fixed in versions 4.2.8 and 4.3.2.