Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2025-30219

RabbitMQ management UI renders an unescaped virtual host name in an error message

Technology

RabbitMQ

CVSS Score

6.1 / 10.0

Affected Versions

3.13.0 to 3.13.7; 4.0.0 to 4.0.2

Upstream Fix

4.0.3 (public); 3.13.8 (commercial)

Published

March 25, 2025

OSSeva Coverage

Fixed upstream

Description

When a virtual host fails to start, the management UI shows a notification that includes the virtual host name, which was not escaped. An attacker able to make a virtual host fail and to create one whose name contains script could run JavaScript in management UI users' browsers. The advisory describes the attack as requiring on-disk file changes. Fixed in 4.0.3 and in the commercial 3.13.8. NVD has not scored the record; the score is GitHub's as the CNA.

Upstream record: NVD · CVE.org

Is your RabbitMQ deployment affected?

If you're running 3.13.0 to 3.13.7; 4.0.0 to 4.0.2, you need this patch. Book a discovery call to get covered.