CVE-2019-11281: Debian Linux
Medium severity, CVSS 4.8. EPSS: 1.2% chance of exploitation in the next 30 days.
Pivotal RabbitMQ, versions prior to v3.7.18, and RabbitMQ for PCF, versions 1.15.x prior to 1.15.13, versions 1.16.x prior to 1.16.6, and versions 1.17.x prior to 1.17.3, contain two components, the virtual host limits page, and the federation management UI, which do not properly sanitize user input. A remote authenticated malicious user with administrative access could craft a cross site scripting attack that would gain access to virtual hosts and policy management information.
Affected products
- Debian Debian Linux: version 9.0 only
- Fedoraproject Fedora: version 30 only; version 31 only
- Pivotal Software Rabbitmq: before 3.7.18 (fixed in 3.7.18); from 1.15.0, before 1.15.13 (fixed in 1.15.13); from 1.16.0, before 1.16.6 (fixed in 1.16.6); from 1.17.0, before 1.17.3 (fixed in 1.17.3)
- Red Hat Openstack: version 15 only
- Red Hat Openstack For IBM Power: version 15 only
Published 2019-10-16. Last modified 2026-06-17.