Pivotal RabbitMQ, versions prior to v3.7.18, and RabbitMQ for PCF, versions 1.15.x prior to 1.15.13, versions 1.16.x prior to 1.16.6, and versions 1.17.x prior to 1.17.3, contain two components, the virtual host limits page, and the federation management UI, which do not properly sanitize user input. A remote authenticated malicious user with administrative access could craft a cross site scripting attack that would gain access to virtual hosts and policy management information.
Conclusion & alert: CVE-2019-11281 is rated Moderate Risk (41.4/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 1.17%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 1.02% | 1.17% | +0.14% |
| 2 | 2025-11-21 | 0.47% | 1.02% | +0.55% |
| 3 | 2025-11-18 | — | 0.47% | — |
Full EPSS history (14 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 4.8 | 3.1 | MEDIUM |
|
1.7 | 2.7 | [email protected] |
| 2.4 | 3.0 | LOW |
|
0.9 | 1.4 | [email protected] |
| 3.5 | 2.0 | LOW |
|
6.8 | 2.9 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
low | CVE-2019-11281 low priority: Debian including 1 source packages (rabbitmq-server), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2019-11281 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2019-11281 |
suse
|
medium | CVE-2019-11281 severity moderate: SUSE including 2 source package names (rabbitmq-server, rabbitmq-server-plugins), 16 product×package rows across 9 product lines (HPE Helion OpenStack 8, HPE Helion OpenStack Cloud 8, … (9 product lines)): Known Not Affected 16. | https://www.suse.com/security/cve/CVE-2019-11281/ |
ubuntu
|
low | CVE-2019-11281 low priority: Ubuntu including 1 source packages (rabbitmq-server), 11 status rows across 11 suites (bionic, disco, eoan, focal, groovy, hirsute, impish, jammy, trusty, upstream, xenial): not-affected 7, ignored 2, DNE 1, needs-triage 1. | https://ubuntu.com/security/CVE-2019-11281 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| pivotal_software | rabbitmq | < 3.7.18 | cpe:2.3:a:pivotal_software:rabbitmq:*:*:*:*:*:*:*:* |
| pivotal_software | rabbitmq | >= 1.15.0, < 1.15.13 | cpe:2.3:a:pivotal_software:rabbitmq:*:*:*:*:*:pivotal_cloud_foundry:*:* |
| pivotal_software | rabbitmq | >= 1.16.0, < 1.16.6 | cpe:2.3:a:pivotal_software:rabbitmq:*:*:*:*:*:pivotal_cloud_foundry:*:* |
| pivotal_software | rabbitmq | >= 1.17.0, < 1.17.3 | cpe:2.3:a:pivotal_software:rabbitmq:*:*:*:*:*:pivotal_cloud_foundry:*:* |
| redhat | openstack | 15 | cpe:2.3:a:redhat:openstack:15:*:*:*:*:*:*:* |
| redhat | openstack_for_ibm_power | 15 | cpe:2.3:a:redhat:openstack_for_ibm_power:15:*:*:*:*:*:*:* |
| debian | debian_linux | 9.0 | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
| fedoraproject | fedora | 30 | cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:* |
| fedoraproject | fedora | 31 | cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* |