← Back

CVE-2019-11291

nvd nist
Published: Nov 22, 2019Modified: Jun 17, 2026

JSON object

Loading...
4.8
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Exploitability: 1.7 / Impact: 2.7
Source: NVD

Description

Pivotal RabbitMQ, 3.7 versions prior to v3.7.20 and 3.8 version prior to v3.8.1, and RabbitMQ for PCF, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain two endpoints, federation and shovel, which do not properly sanitize user input. A remote authenticated malicious user with administrative access could craft a cross site scripting attack via the vhost or node name fields that could grant access to virtual hosts and policy management information.

Affected (5)

1 product
Rabbitmq Server
1 product
Rabbitmq
1 product
Openstack
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Broadcom
From 3.7.0 to 3.7.20
Version 3.8.0
Vmware
From 1.16.0 to 1.16.7
From 1.17.0 to 1.17.4
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 15

References (4)

Source: security@pivotal.io
Third Party Advisory
Source: security@pivotal.io
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.