Bug 915325 (CVE-2014-9649) - VUL-0: CVE-2014-9649 RabbitMQ: /api/... XSS vulnerability
Summary: VUL-0: CVE-2014-9649 RabbitMQ: /api/... XSS vulnerability
Status: RESOLVED FIXED
Alias: CVE-2014-9649
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Deadline: 2015-03-12
Assignee: Dirk Mueller
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/113204/
Whiteboard: CVSSv2:RedHat:CVE-2014-9649:4.3:(AV:N...
Keywords:
Depends on:
Blocks:
 
Reported: 2015-01-29 09:29 UTC by Victor Pereira
Modified: 2017-08-04 09:25 UTC (History)
9 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Victor Pereira 2015-01-29 09:29:03 UTC
rh#1185514

Cross-site scripting (XSS) vulnerability in the management plugin in RabbitMQ
2.1.0 through 3.4.x before 3.4.1 allows remote attackers to inject arbitrary web
script or HTML via the path info to api/, which is not properly handled in an
error message.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1185514
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-9649
http://seclists.org/oss-sec/2015/q1/273
http://www.openwall.com/lists/oss-security/2015/01/21/13
http://people.canonical.com/~ubuntu-security/cve/2014/CVE-2014-9649.html
https://groups.google.com/forum/#!topic/rabbitmq-users/-3Z2FyGtXhs
http://www.rabbitmq.com/release-notes/README-3.4.1.txt
Comment 1 Swamp Workflow Management 2015-01-29 23:00:35 UTC
bugbot adjusting priority
Comment 2 Swamp Workflow Management 2015-02-26 15:25:44 UTC
An update workflow for this issue was started.
This issue was rated as moderate.
Please submit fixed packages until 2015-03-12.
When done, reassign the bug to security-team@suse.de.
https://swamp.suse.de/webswamp/wf/60836
Comment 5 Vincent Untz 2015-03-17 08:40:50 UTC
Cloud 5 is not affected afaict, Cloud 4 needs a fix.
Comment 12 Bernhard Wiedemann 2015-07-07 14:13:34 UTC
update is still stuck in maintenance-QA :-(
Comment 15 Andreas Stieger 2016-12-30 17:36:44 UTC
This is still open for:
openSUSE 13.2      3.3.5
Already fixed later.

Assigning to openSUSE maintainer. Please indicate if you want to fix this in 13.2.
Comment 16 Johannes Segitz 2017-08-04 09:25:56 UTC
fixed in current products, Leap and Factory