CVE-2019-11291 is a cross-site scripting (XSS) vulnerability affecting Pivotal RabbitMQ versions prior to 3.7.20 and 3.8.1, and RabbitMQ for PCF versions prior to 1.16.7 and 1.17.4, as well as various Broadcom, Red Hat, and VMware OpenStack and RabbitMQ products. The vulnerability, rated Medium severity (CVSS 4.8), allows a remote authenticated administrative user to inject malicious scripts via unsanitized user input in federation and shovel endpoints. Successful exploitation could lead to unauthorized access to virtual host and policy management information, with low impact on confidentiality and integrity. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.7.0, < 3.7.20CPE matchmatch criteria | cpe:2.3:a:broadcom:rabbitmq_server:*:*:*:*:*:*:*:* | ||
3.8.0CPE matchmatch criteria | cpe:2.3:a:broadcom:rabbitmq_server:3.8.0:*:*:*:*:*:*:* | ||
>= 1.16.0, < 1.16.7CPE matchmatch criteria | cpe:2.3:a:vmware:rabbitmq:*:*:*:*:*:pivotal_cloud_foundry:*:* | ||
>= 1.17.0, < 1.17.4CPE matchmatch criteria | cpe:2.3:a:vmware:rabbitmq:*:*:*:*:*:pivotal_cloud_foundry:*:* | ||
15CPE matchmatch criteria | cpe:2.3:a:redhat:openstack:15:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.