CVE-2014-9494
20.01.2015, 15:59
RabbitMQ before 3.4.0 allows remote attackers to bypass the loopback_users restriction via a crafted X-Forwareded-For header.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| pivotal_software | rabbitmq | 𝑥 ≤ 3.3.5 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| erlang-rabbitmq-client |
| ||||||||||||||||
| erlang-rabbitmq-client313 |
| ||||||||||||||||
| rabbitmq-server |
| ||||||||||||||||
| rabbitmq-server-plugins |
| ||||||||||||||||
| rabbitmq-server313 |
| ||||||||||||||||
| rabbitmq-server313-bash-completion |
| ||||||||||||||||
| rabbitmq-server313-plugins |
| ||||||||||||||||
| rabbitmq-server313-zsh-completion |
|
Common Weakness Enumeration
References