Alerts This Week
Warning Icon 1 1,154
Alerts This Week
Warning Icon 1 1,154

Ubuntu 7399-1: RabbitMQ Server Security Advisory Updates

ubuntu
Calendar Grey March 31, 2025
Dist Ubuntu Esm H88
RabbitMQ Server's management UI has a critical XSS flaw requiring updates for Ubuntu 20.04 to 24.10 to mitigate risks.
RabbitMQ Server's management UI could be made to run code via cross-site scripting (XSS).

Summary

RabbitMQ Server's management UI could be made to run code via

cross-site scripting (XSS).

Software Description:

- rabbitmq-server: AMQP server written in Erlang

Details:

It was discovered that RabbitMQ Server's management UI did not sanitize

certain input. An attacker could possibly use this issue to inject code

by performing a cross-site scripting (XSS) attack.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 24.10
   rabbitmq-server                 3.12.1-1ubuntu2.1

Ubuntu 24.04 LTS
   rabbitmq-server                 3.12.1-1ubuntu1.2

Ubuntu 22.04 LTS
   rabbitmq-server                 3.9.27-0ubuntu0.2

Ubuntu 20.04 LTS
   rabbitmq-server                 3.8.3-0ubuntu0.3

After a standard system update you need to restart RabbitMQ Server to make
all the necessary changes.

References

  https://ubuntu.com/security/notices/USN-7399-1

  CVE-2025-30219

Severity
important
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-7399-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here