GHSA-9pf7-f47q-mwpq · Severity: low · Ecosystem: erlang — Cross-site Scripting in RabbitMQ
Pivotal RabbitMQ, 3.7 versions prior to v3.7.20 and 3.8 version prior to v3.8.1, and RabbitMQ for PCF, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain two endpoints, federation and shovel, which do not properly sanitize user input. A remote authenticated malicious user with administrative access could craft a cross site scripting attack via the vhost or node name fields that could grant access to virtual hosts and policy management information.
Conclusion & alert: CVE-2019-11291 is rated Moderate Risk (41.5/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 0.52%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-04-13 | 0.68% | 0.52% | -0.16% |
| 2 | 2025-04-05 | 0.52% | 0.68% | +0.16% |
| 3 | 2025-04-03 | — | 0.52% | — |
Full EPSS history (12 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 4.8 | 3.1 | MEDIUM |
|
1.7 | 2.7 | [email protected] |
| 3.1 | 3.0 | LOW |
|
0.5 | 2.5 | [email protected] |
| 3.5 | 2.0 | LOW |
|
6.8 | 2.9 | [email protected] |
GHSA-9pf7-f47q-mwpq · Severity: low · Ecosystem: erlang — Cross-site Scripting in RabbitMQ
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2019-11291 not yet assigned priority: Debian including 1 source packages (rabbitmq-server), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2019-11291 |
redhat
|
low | — | https://access.redhat.com/security/cve/CVE-2019-11291 |
suse
|
medium | CVE-2019-11291 severity moderate: SUSE including 2 source package names (rabbitmq-server, rabbitmq-server-plugins), 16 product×package rows across 9 product lines (HPE Helion OpenStack 8, HPE Helion OpenStack Cloud 8, … (9 product lines)): Known Not Affected 16. | https://www.suse.com/security/cve/CVE-2019-11291/ |
ubuntu
|
low | CVE-2019-11291 low priority: Ubuntu including 1 source packages (rabbitmq-server), 6 status rows across 6 suites (bionic, focal, groovy, trusty, upstream, xenial): not-affected 4, DNE 1, needs-triage 1. | https://ubuntu.com/security/CVE-2019-11291 |
: A remote authenticated malicious user with administrative access
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| broadcom | rabbitmq_server | >= 3.7.0, < 3.7.20 | cpe:2.3:a:broadcom:rabbitmq_server:*:*:*:*:*:*:*:* |
| broadcom | rabbitmq_server | 3.8.0 | cpe:2.3:a:broadcom:rabbitmq_server:3.8.0:*:*:*:*:*:*:* |
| vmware | rabbitmq | >= 1.16.0, < 1.16.7 | cpe:2.3:a:vmware:rabbitmq:*:*:*:*:*:pivotal_cloud_foundry:*:* |
| vmware | rabbitmq | >= 1.17.0, < 1.17.4 | cpe:2.3:a:vmware:rabbitmq:*:*:*:*:*:pivotal_cloud_foundry:*:* |
| redhat | openstack | 15 | cpe:2.3:a:redhat:openstack:15:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://access.redhat.com/errata/RHSA-2020:0553 | Third Party Advisory |
| https://pivotal.io/security/cve-2019-11291 | Vendor Advisory |