VDB
BDU%3A2025-04152
BDU%3A2025-04152
PUBLISHED
CVSS 3.5 LOW
Уязвимость брокера сообщений RabbitMQ, связанная с непринятием мер по нейтрализации script-related тэгов html на веб-странице, позволяющая нарушителю оказать воздействие на целостность данных
Risk Scores
CVSS 2.0
3.5
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Сообщество свободного программного обеспечения, ООО «РусБИТех-Астра», Pivotal Software Inc. | Debian GNU/Linux, Astra Linux Special Edition (запись в едином реестре российских программ №369), RabbitMQ |
Timeline
- Apr 10, 2025 CVE Published
- May 5, 2025 CVE Updated
References
- http://seclists.org/fulldisclosure/2021/Dec/3 url
- https://github.com/rabbitmq/rabbitmq-server/commit/a7373585faeac0aaede5a9c245094d8022e81299 url
- https://github.com/rabbitmq/rabbitmq-server/commit/a8dffdf7de9793a76fc4685c89b968d8eddca4ca url
- https://github.com/rabbitmq/rabbitmq-server/pull/3028 url
- https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-c3hj-rg5h-2772 url
- https://nvd.nist.gov/vuln/detail/CVE-2021-32718 url
- https://security-tracker.debian.org/tracker/CVE-2021-32718 url
- https://wiki.astralinux.ru/astra-linux-se17-bulletin-2025-0319SE17 url
- https://wiki.astralinux.ru/astra-linux-se47-bulletin-2025-0422SE77 url
- https://wiki.astralinux.ru/astra-linux-se47-bulletin-2025-0422SE47 advisory