Description
CRLF injection vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the download parameter to api/definitions.
Related CPE's
a
broadcom
rabbitmq_server
44
References
http://www.openwall.com/lists/oss-security/2015/01/21/13
Mailing ListThird Party Advisory
http://www.rabbitmq.com/release-notes/README-3.4.1.txt
Vendor Advisory
http://www.openwall.com/lists/oss-security/2015/01/21/13
Mailing ListThird Party Advisory
http://www.rabbitmq.com/release-notes/README-3.4.1.txt
Vendor Advisory
CVSS impact metrics
AV:N/AC:L/Au:N/C:N/I:P/A:N
5 · Medium
Information
Source identifier
Vulnerability status
Modified
Published
2015-01-27T20:03:15.080Z
11 years agoLast modified
2026-06-17T00:18:43.063Z
3 months ago