CyberRota Analysis
AI-GeneratedRabbitMQ versions 3.13.0 to 3.13.18 and 4.0.23, 4.1.14, 4.2.9, and 4.3.3 are vulnerable to a stored XSS attack via the TLS peer-certificate DN in the stream-management UI, which can be exploited by an attacker with a maliciously crafted certificate. This vulnerability requires a non-default configuration with a TLS listener that verifies peer certificates, allowing an attacker to execute arbitrary scripts when an operator views the stream-connection details. Organizations using these RabbitMQ versions with TLS enabled should prioritize upgrading to the patched versions to mitigate the risk of exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.18 and 4.0.23 and 4.1.14 and 4.2.9 and 4.3.3, Stored XSS via TLS peer-certificate DN in stream-management UI (sibling of V-11). lines 102/106/110 render peercertsubject / peercertissuer with raw <%= %> and no fmtstring(). RFC4514 backslash-escaping of </> is HTML-inert and bypassable (<img ... //>). Requires non-default config: a stream TLS listener with verifypeer and an attacker-obtainable trusted cert with a malicious Same as the connection.ejs finding, against operators viewing the stream-connection detail rabbitmqstream + rabbitmqstreammanagement enabled with a TLS listener using verifypeer Attacker can obtain a certificate signed by a CA the listener trusts, with attacker-chosen DN An operator views the. This issue is fixed in versions 3.13.18 and 4.0.23 and 4.1.14 and 4.2.9 and 4.3.3.