CVE-2014-9494

RabbitMQ before 3.4.0 allows remote attackers to bypass the loopback_users restriction via a crafted X-Forwareded-For header.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 60%
Affected Products (NVD)
VendorProductVersion
pivotal_softwarerabbitmq
𝑥
≤ 3.3.5
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
rabbitmq-server
bookworm
3.10.8-1.1+deb12u1
fixed
bookworm (security)
3.10.8-1.1+deb12u1
fixed
bullseye
3.8.9-3+deb11u1
fixed
bullseye (security)
3.8.9-3+deb11u1
fixed
sid
3.10.8-3
fixed
squeeze
not-affected
trixie
3.10.8-3
fixed
wheezy
not-affected
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
rabbitmq-server
lucid
ignored
precise
not-affected
trusty
dne
utopic
ignored
vivid
not-affected
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
erlang-rabbitmq-client
suse enterprise sap 15 SP2
3.8.3-1.27
fixed
suse enterprise sap 15 SP3
3.8.11-1.26
fixed
suse enterprise sap 15 SP4
3.8.11-3.3.3
fixed
suse enterprise sap 15 SP7
3.8.11-150300.3.14.1
fixed
suse enterprise server 15 SP2
3.8.3-1.27
fixed
suse enterprise server 15 SP3
3.8.11-1.26
fixed
suse enterprise server 15 SP4
3.8.11-3.3.3
fixed
suse enterprise server 15 SP7
3.8.11-150300.3.14.1
fixed
erlang-rabbitmq-client313
suse enterprise sap 15 SP7
3.13.1-150600.13.5.3
fixed
suse enterprise server 15 SP7
3.13.1-150600.13.5.3
fixed
rabbitmq-server
suse enterprise sap 15 SP2
3.8.3-1.27
fixed
suse enterprise sap 15 SP3
3.8.11-1.26
fixed
suse enterprise sap 15 SP4
3.8.11-3.3.3
fixed
suse enterprise sap 15 SP7
3.8.11-150300.3.14.1
fixed
suse enterprise server 15 SP2
3.8.3-1.27
fixed
suse enterprise server 15 SP3
3.8.11-1.26
fixed
suse enterprise server 15 SP4
3.8.11-3.3.3
fixed
suse enterprise server 15 SP7
3.8.11-150300.3.14.1
fixed
rabbitmq-server-plugins
suse enterprise sap 15 SP2
3.8.3-1.27
fixed
suse enterprise sap 15 SP3
3.8.11-1.26
fixed
suse enterprise sap 15 SP4
3.8.11-3.3.3
fixed
suse enterprise sap 15 SP7
3.8.11-150300.3.14.1
fixed
suse enterprise server 15 SP2
3.8.3-1.27
fixed
suse enterprise server 15 SP3
3.8.11-1.26
fixed
suse enterprise server 15 SP4
3.8.11-3.3.3
fixed
suse enterprise server 15 SP7
3.8.11-150300.3.14.1
fixed
rabbitmq-server313
suse enterprise sap 15 SP7
3.13.1-150600.13.5.3
fixed
suse enterprise server 15 SP7
3.13.1-150600.13.5.3
fixed
rabbitmq-server313-bash-completion
suse enterprise sap 15 SP7
3.13.1-150600.13.5.3
fixed
suse enterprise server 15 SP7
3.13.1-150600.13.5.3
fixed
rabbitmq-server313-plugins
suse enterprise sap 15 SP7
3.13.1-150600.13.5.3
fixed
suse enterprise server 15 SP7
3.13.1-150600.13.5.3
fixed
rabbitmq-server313-zsh-completion
suse enterprise sap 15 SP7
3.13.1-150600.13.5.3
fixed
suse enterprise server 15 SP7
3.13.1-150600.13.5.3
fixed
Common Weakness Enumeration