CVE-2021-32718
Summary
| CVE | CVE-2021-32718 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-06-28 15:15:00 UTC |
| Updated | 2021-12-10 19:57:00 UTC |
| Description | RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.17, a new user being added via management UI could lead to the user's bane being rendered in a confirmation message without proper `<script>` tag sanitization, potentially allowing for JavaScript code execution in the context of the page. In order for this to occur, the user must be signed in and have elevated permissions (other user management). The vulnerability is patched in RabbitMQ 3.8.17. As a workaround, disable `rabbitmq_management` plugin and use CLI tools for management operations and Prometheus and Grafana for metrics and monitoring. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Escape username before displaying it in a pop-up message by michaelklishin · Pull Request #3028 · rabbitmq/rabbitmq-server · GitHub | MISC | github.com | |
| Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in RabbitMQ management UI · Advisory · rabbitmq/rabbitmq-server · GitHub | CONFIRM | github.com | |
| Full Disclosure: usd AG Security Advisories 11/2021 | FULLDISC | seclists.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 183791 Debian Security Update for rabbitmq-server (CVE-2021-32718)
- 240980 Red Hat Update for OpenStack Platform 16.2.4 (RHSA-2022:8851)
- 240982 Red Hat Update for OpenStack Platform 16.1.9 (RHSA-2022:8867)
- 751191 OpenSUSE Security Update for rabbitmq-server (openSUSE-SU-2021:1334-1)
- 751206 OpenSUSE Security Update for rabbitmq-server (openSUSE-SU-2021:3325-1)