Vulnerability record · CVE-2019-11291 · published 22 November 2019
CVE-2019-11291: Broadcom rabbitmq server cross-site scripting vulnerability
Broadcom · Rabbitmq Server
Pivotal RabbitMQ, 3.7 versions prior to v3.7.20 and 3.8 version prior to v3.8.1, and RabbitMQ for PCF, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain two endpoints, federation and shovel, which do not properly sanitize user input. A remote authenticated malicious user with administrative access could craft a cross site scripting attack via the vhost or node name fields that could grant access to virtual hosts and policy management information.
Description
Pivotal RabbitMQ, 3.7 versions prior to v3.7.20 and 3.8 version prior to v3.8.1, and RabbitMQ for PCF, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain two endpoints, federation and shovel, which do not properly sanitize user input. A remote authenticated malicious user with administrative access could craft a cross site scripting attack via the vhost or node name fields that could grant access to virtual hosts and policy management information.
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://access.redhat.com/errata/RHSA-2020:0553 | Third Party Advisory |
| https://pivotal.io/security/cve-2019-11291 | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2020:0553 | Third Party Advisory |
| https://pivotal.io/security/cve-2019-11291 | Vendor Advisory |
Track CVE-2019-11291 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-11291), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.