Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2014-9650

CRLF injection vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the download parameter to api/definitions.

  • Published: Jan 27, 2015
  • Updated: Apr 13, 2023
  • CVE: CVE-2014-9650
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 5
  • AV:N/AC:L/Au:N/C:N/I:P/A:N

No CWE or OWASP classifications available.

Software From Fixed in
vmware / rabbitmq 2.1.0 2.1.0.x
vmware / rabbitmq 2.1.1 2.1.1.x
vmware / rabbitmq 2.4.1 2.4.1.x
vmware / rabbitmq 2.5.0 2.5.0.x
vmware / rabbitmq 2.5.1 2.5.1.x
vmware / rabbitmq 2.6.0 2.6.0.x
vmware / rabbitmq 2.2.0 2.2.0.x
vmware / rabbitmq 2.3.0 2.3.0.x
vmware / rabbitmq 2.3.1 2.3.1.x
vmware / rabbitmq 2.4.0 2.4.0.x
vmware / rabbitmq 2.8.1 2.8.1.x
vmware / rabbitmq 2.8.2 2.8.2.x
vmware / rabbitmq 2.8.3 2.8.3.x
vmware / rabbitmq 2.8.4 2.8.4.x
vmware / rabbitmq 2.6.1 2.6.1.x
vmware / rabbitmq 2.7.0 2.7.0.x
vmware / rabbitmq 2.7.1 2.7.1.x
vmware / rabbitmq 2.8.0 2.8.0.x
vmware / rabbitmq 3.0.1 3.0.1.x
vmware / rabbitmq 3.0.2 3.0.2.x
vmware / rabbitmq 3.0.3 3.0.3.x
vmware / rabbitmq 3.0.4 3.0.4.x
vmware / rabbitmq 2.8.5 2.8.5.x
vmware / rabbitmq 2.8.6 2.8.6.x
vmware / rabbitmq 2.8.7 2.8.7.x
vmware / rabbitmq 3.0.0 3.0.0.x
vmware / rabbitmq 3.1.4 3.1.4.x
vmware / rabbitmq 3.1.5 3.1.5.x
vmware / rabbitmq 3.2.0 3.2.0.x
vmware / rabbitmq 3.1.0 3.1.0.x
vmware / rabbitmq 3.1.1 3.1.1.x
vmware / rabbitmq 3.1.2 3.1.2.x
vmware / rabbitmq 3.1.3 3.1.3.x
vmware / rabbitmq 3.3.5 3.3.5.x
vmware / rabbitmq 3.2.1 3.2.1.x
vmware / rabbitmq 3.3.1 3.3.1.x
vmware / rabbitmq 3.3.2 3.3.2.x
vmware / rabbitmq 3.3.3 3.3.3.x
vmware / rabbitmq 3.3.4 3.3.4.x
vmware / rabbitmq 3.2.2 3.2.2.x
vmware / rabbitmq 3.2.3 3.2.3.x
vmware / rabbitmq 3.2.4 3.2.4.x
vmware / rabbitmq 3.3.0 3.3.0.x
vmware / rabbitmq 3.4.0 3.4.0.x