Your submission was sent successfully! Close

CVE-2014-9494

Published: 20 January 2015

RabbitMQ before 3.4.0 allows remote attackers to bypass the loopback_users restriction via a crafted X-Forwareded-For header.

Notes

AuthorNote
mdeslaur
3.3.0 and higher
Priority

Low

Status

Package Release Status
rabbitmq-server
Launchpad, Ubuntu, Debian
lucid Ignored
(reached end-of-life)
precise Not vulnerable
(2.7.1-0ubuntu4)
trusty Does not exist
(trusty was not-affected [3.2.4-1])
upstream
Released (3.4.1-1)
utopic Ignored
(reached end-of-life)
vivid Not vulnerable
(3.4.1-1)
wily Not vulnerable
(3.4.1-1)
Patches:
upstream: http://hg.rabbitmq.com/rabbitmq-management/rev/c3c41177a11a
upstream: http://hg.rabbitmq.com/rabbitmq-management/rev/35e916df027d
upstream: https://github.com/rabbitmq/rabbitmq-management/commit/2fc7e9a7b7349246a62d088633234be6f313f556
upstream: https://github.com/rabbitmq/rabbitmq-management/commit/3c8073a113d99c343d0ef47abe48b0c4175a4d1a