CVE-2021-32718
RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.17, a new user being added via management UI could lead to the user's bane being rendered in a confirmation message without proper `<script>` tag sanitization, potentially allowing for JavaScript code execution in the context of the page. In order for this to occur, the user must be signed in and have elevated permissions (other user management). The vulnerability is patched in RabbitMQ 3.8.17. As a workaround, disable `rabbitmq_management` plugin and use CLI tools for management operations and Prometheus and Grafana for metrics and monitoring.
EPSS 0.12% · 30.0th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | rabbitmq | 0 |
| Bitnami | rabbitmq | 0 |
Exploit Intelligence
Timeline
- Jun 27, 2021 CVE Published
- Jun 29, 2021 EPSS Score
- Aug 28, 2021 EPSS Score
- Oct 27, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 25, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Apr 26, 2022 EPSS Score
- Jun 25, 2022 EPSS Score
- Aug 25, 2022 EPSS Score
- Oct 24, 2022 EPSS Score