openSUSE-SU-2021:1334-1
Dashboard / Vulnerabilities / openSUSE-SU-2021:1334-1
openSUSE-SU-2021:1334-1
Summary: Security update for rabbitmq-server
Details: This update for rabbitmq-server fixes the following issues: - CVE-2021-32718: Fixed improper neutralization of script-related HTML tags in a web page (basic XSS) in management UI (bsc#1187818). - CVE-2021-32719: Fixed improper neutralization of script-related HTML tags in a web page (basic XSS) in federation management plugin (bsc#1187819). - CVE-2021-22116: Fixed improper input validation may lead to DoS (bsc#1186203). - Use /run instead of /var/run in tmpfiles.d configuration (bsc#1185075). This update was imported from the SUSE:SLE-15-SP2:Update update project.
References: https://lists.opensuse.org/archives/list/[email protected]/thread/FWIIK75CV5Y6TWUXN67IYXFNHIHRZSXN/, https://bugzilla.suse.com/1185075, https://bugzilla.suse.com/1186203, https://bugzilla.suse.com/1187818, https://bugzilla.suse.com/1187819, https://www.suse.com/security/cve/CVE-2021-22116, https://www.suse.com/security/cve/CVE-2021-32718, https://www.suse.com/security/cve/CVE-2021-32719
Affected packages
Package
Name: rabbitmq-server
Purl: pkg:rpm/opensuse/rabbitmq-server&distro=openSUSE%20Leap%2015.2
Affected ranges
Type: ECOSYSTEM
Events:
