CVE-2025-30219
RabbitMQ management UI renders an unescaped virtual host name in an error message
Technology
RabbitMQ
CVSS Score
6.1 / 10.0
Affected Versions
3.13.0 to 3.13.7; 4.0.0 to 4.0.2
Upstream Fix
4.0.3 (public); 3.13.8 (commercial)
Published
March 25, 2025
OSSeva Coverage
Fixed upstream
Description
When a virtual host fails to start, the management UI shows a notification that includes the virtual host name, which was not escaped. An attacker able to make a virtual host fail and to create one whose name contains script could run JavaScript in management UI users' browsers. The advisory describes the attack as requiring on-disk file changes. Fixed in 4.0.3 and in the commercial 3.13.8. NVD has not scored the record; the score is GitHub's as the CNA.
Is your RabbitMQ deployment affected?
If you're running 3.13.0 to 3.13.7; 4.0.0 to 4.0.2, you need this patch. Book a discovery call to get covered.