Cross-site Scripting (XSS) Affecting rabbitmq-server313 package, versions <3.13.1-150600.13.8.1


Severity

Recommended
0.0
medium
0
10

Based on SUSE Linux Enterprise Server security rating.

Threat Intelligence

EPSS
0.11% (31st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Cross-site Scripting (XSS) vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-SLES156-RABBITMQSERVER313-10169628
  • published15 May 2025
  • disclosed14 May 2025

Introduced: 14 May 2025

NewCVE-2025-30219  (opens in a new tab)
CWE-79  (opens in a new tab)

How to fix?

Upgrade SLES:15.6 rabbitmq-server313 to version 3.13.1-150600.13.8.1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream rabbitmq-server313 package and not the rabbitmq-server313 package as distributed by SLES. See How to fix? for SLES:15.6 relevant fixed versions and status.

RabbitMQ is a messaging and streaming broker. Versions prior to 4.0.3 are vulnerable to a sophisticated attack that could modify virtual host name on disk and then make it unrecoverable (with other on disk file modifications) can lead to arbitrary JavaScript code execution in the browsers of management UI users. When a virtual host on a RabbitMQ node fails to start, recent versions will display an error message (a notification) in the management UI. The error message includes virtual host name, which was not escaped prior to open source RabbitMQ 4.0.3 and Tanzu RabbitMQ 4.0.3, 3.13.8. An attack that both makes a virtual host fail to start and creates a new virtual host name with an XSS code snippet or changes the name of an existing virtual host on disk could trigger arbitrary JavaScript code execution in the management UI (the user's browser). Open source RabbitMQ 4.0.3 and Tanzu RabbitMQ 4.0.3 and 3.13.8 patch the issue.

CVSS Base Scores

version 3.1