CVE Vulnerabilities

CVE-2014-9650

Published: Jan 27, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

CRLF injection vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the download parameter to api/definitions.

Affected Software

NameVendorStart VersionEnd Version
Rabbitmq_serverBroadcom2.1.0 (including)2.1.0 (including)
Rabbitmq_serverBroadcom2.1.1 (including)2.1.1 (including)
Rabbitmq_serverBroadcom2.2.0 (including)2.2.0 (including)
Rabbitmq_serverBroadcom2.3.0 (including)2.3.0 (including)
Rabbitmq_serverBroadcom2.3.1 (including)2.3.1 (including)
Rabbitmq_serverBroadcom2.4.0 (including)2.4.0 (including)
Rabbitmq_serverBroadcom2.4.1 (including)2.4.1 (including)
Rabbitmq_serverBroadcom2.5.0 (including)2.5.0 (including)
Rabbitmq_serverBroadcom2.5.1 (including)2.5.1 (including)
Rabbitmq_serverBroadcom2.6.0 (including)2.6.0 (including)
Rabbitmq_serverBroadcom2.6.1 (including)2.6.1 (including)
Rabbitmq_serverBroadcom2.7.0 (including)2.7.0 (including)
Rabbitmq_serverBroadcom2.7.1 (including)2.7.1 (including)
Rabbitmq_serverBroadcom2.8.0 (including)2.8.0 (including)
Rabbitmq_serverBroadcom2.8.1 (including)2.8.1 (including)
Rabbitmq_serverBroadcom2.8.2 (including)2.8.2 (including)
Rabbitmq_serverBroadcom2.8.3 (including)2.8.3 (including)
Rabbitmq_serverBroadcom2.8.4 (including)2.8.4 (including)
Rabbitmq_serverBroadcom2.8.5 (including)2.8.5 (including)
Rabbitmq_serverBroadcom2.8.6 (including)2.8.6 (including)
Rabbitmq_serverBroadcom2.8.7 (including)2.8.7 (including)
Rabbitmq_serverBroadcom3.0.0 (including)3.0.0 (including)
Rabbitmq_serverBroadcom3.0.1 (including)3.0.1 (including)
Rabbitmq_serverBroadcom3.0.2 (including)3.0.2 (including)
Rabbitmq_serverBroadcom3.0.3 (including)3.0.3 (including)
Rabbitmq_serverBroadcom3.0.4 (including)3.0.4 (including)
Rabbitmq_serverBroadcom3.1.0 (including)3.1.0 (including)
Rabbitmq_serverBroadcom3.1.1 (including)3.1.1 (including)
Rabbitmq_serverBroadcom3.1.2 (including)3.1.2 (including)
Rabbitmq_serverBroadcom3.1.3 (including)3.1.3 (including)
Rabbitmq_serverBroadcom3.1.4 (including)3.1.4 (including)
Rabbitmq_serverBroadcom3.1.5 (including)3.1.5 (including)
Rabbitmq_serverBroadcom3.2.0 (including)3.2.0 (including)
Rabbitmq_serverBroadcom3.2.1 (including)3.2.1 (including)
Rabbitmq_serverBroadcom3.2.2 (including)3.2.2 (including)
Rabbitmq_serverBroadcom3.2.3 (including)3.2.3 (including)
Rabbitmq_serverBroadcom3.2.4 (including)3.2.4 (including)
Rabbitmq_serverBroadcom3.3.0 (including)3.3.0 (including)
Rabbitmq_serverBroadcom3.3.1 (including)3.3.1 (including)
Rabbitmq_serverBroadcom3.3.2 (including)3.3.2 (including)
Rabbitmq_serverBroadcom3.3.3 (including)3.3.3 (including)
Rabbitmq_serverBroadcom3.3.4 (including)3.3.4 (including)
Rabbitmq_serverBroadcom3.3.5 (including)3.3.5 (including)
Rabbitmq_serverBroadcom3.4.0 (including)3.4.0 (including)
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6RedHatrabbitmq-server-0:3.1.5-6.1.el6ost*
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7RedHatrabbitmq-server-0:3.3.5-18.el7ost*
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7RedHatrabbitmq-server-0:3.3.5-18.el7ost*
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7RedHatrabbitmq-server-0:3.3.5-18.el7ost*
Rabbitmq-serverUbuntulucid*
Rabbitmq-serverUbuntuprecise*
Rabbitmq-serverUbuntutrusty*
Rabbitmq-serverUbuntuupstream*
Rabbitmq-serverUbuntuutopic*

References