SUSE-SU-2021:3254-1
Dashboard / Vulnerabilities / SUSE-SU-2021:3254-1
SUSE-SU-2021:3254-1
Summary: Security update for rabbitmq-server
Details: This update for rabbitmq-server fixes the following issues: - CVE-2021-32718: Fixed improper neutralization of script-related HTML tags in a web page (basic XSS) in management UI (bsc#1187818). - CVE-2021-32719: Fixed improper neutralization of script-related HTML tags in a web page (basic XSS) in federation management plugin (bsc#1187819). - CVE-2021-22116: Fixed improper input validation may lead to DoS (bsc#1186203). - Use /run instead of /var/run in tmpfiles.d configuration (bsc#1185075).
References: https://www.suse.com/support/update/announcement/2021/suse-su-20213254-1/, https://bugzilla.suse.com/1185075, https://bugzilla.suse.com/1186203, https://bugzilla.suse.com/1187818, https://bugzilla.suse.com/1187819, https://www.suse.com/security/cve/CVE-2021-22116, https://www.suse.com/security/cve/CVE-2021-32718, https://www.suse.com/security/cve/CVE-2021-32719
Affected packages
Package
Name: rabbitmq-server
Purl: pkg:rpm/suse/rabbitmq-server&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP2
Affected ranges
Type: ECOSYSTEM
Events:
