Vulnerabilities (CVE)

Filtered by vendor Pivotal Software Subscribe
Filtered by product Rabbitmq
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-9494 1 Pivotal Software 1 Rabbitmq 2018-08-13 5.0 MEDIUM N/A
RabbitMQ before 3.4.0 allows remote attackers to bypass the loopback_users restriction via a crafted X-Forwareded-For header.
CVE-2014-9649 1 Pivotal Software 1 Rabbitmq 2018-08-13 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows remote attackers to inject arbitrary web script or HTML via the path info to api/, which is not properly handled in an error message.
CVE-2014-9650 1 Pivotal Software 1 Rabbitmq 2018-08-13 5.0 MEDIUM N/A
CRLF injection vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the download parameter to api/definitions.