CVE-2014-9649
EPSS 0.30%
Description
Cross-site scripting (XSS) vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows remote attackers to inject arbitrary web script or HTML via the path info to api/, which is not properly handled in an error message.
How to fix CVE-2014-9649
To remediate CVE-2014-9649, upgrade the affected package to a fixed version below.
- Debian/rabbitmq-server—upgrade to 3.4.1-1 or later
Is CVE-2014-9649 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 3.4.1-1