CVE Vulnerabilities

CVE-2014-9650

Published: Jan 27, 2015 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

CRLF injection vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the download parameter to api/definitions.

Affected Software

Name Vendor Start Version End Version
Rabbitmq Vmware 2.1.0 2.1.0
Rabbitmq Vmware 2.1.1 2.1.1
Rabbitmq Vmware 2.4.1 2.4.1
Rabbitmq Vmware 2.5.0 2.5.0
Rabbitmq Vmware 2.5.1 2.5.1
Rabbitmq Vmware 2.6.0 2.6.0
Rabbitmq Vmware 2.2.0 2.2.0
Rabbitmq Vmware 2.3.0 2.3.0
Rabbitmq Vmware 2.3.1 2.3.1
Rabbitmq Vmware 2.4.0 2.4.0
Rabbitmq Vmware 2.8.1 2.8.1
Rabbitmq Vmware 2.8.2 2.8.2
Rabbitmq Vmware 2.8.3 2.8.3
Rabbitmq Vmware 2.8.4 2.8.4
Rabbitmq Vmware 2.6.1 2.6.1
Rabbitmq Vmware 2.7.0 2.7.0
Rabbitmq Vmware 2.7.1 2.7.1
Rabbitmq Vmware 2.8.0 2.8.0
Rabbitmq Vmware 3.0.1 3.0.1
Rabbitmq Vmware 3.0.2 3.0.2
Rabbitmq Vmware 3.0.3 3.0.3
Rabbitmq Vmware 3.0.4 3.0.4
Rabbitmq Vmware 2.8.5 2.8.5
Rabbitmq Vmware 2.8.6 2.8.6
Rabbitmq Vmware 2.8.7 2.8.7
Rabbitmq Vmware 3.0.0 3.0.0
Rabbitmq Vmware 3.1.4 3.1.4
Rabbitmq Vmware 3.1.5 3.1.5
Rabbitmq Vmware 3.2.0 3.2.0
Rabbitmq Vmware 3.1.0 3.1.0
Rabbitmq Vmware 3.1.1 3.1.1
Rabbitmq Vmware 3.1.2 3.1.2
Rabbitmq Vmware 3.1.3 3.1.3
Rabbitmq Vmware 3.3.5 3.3.5
Rabbitmq Vmware 3.2.1 3.2.1
Rabbitmq Vmware 3.3.1 3.3.1
Rabbitmq Vmware 3.3.2 3.3.2
Rabbitmq Vmware 3.3.3 3.3.3
Rabbitmq Vmware 3.3.4 3.3.4
Rabbitmq Vmware 3.2.2 3.2.2
Rabbitmq Vmware 3.2.3 3.2.3
Rabbitmq Vmware 3.2.4 3.2.4
Rabbitmq Vmware 3.3.0 3.3.0
Rabbitmq Vmware 3.4.0 3.4.0

References