CVE-2025-30219

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Mar 25, 2025
Updated: Mar 27, 2025
CWE ID 79

Summary

CVE-2025-30219 is a vulnerability affecting RabbitMQ versions prior to 4.0.3. This issue allows an attacker to modify a virtual host name on disk and make it unrecoverable, leading to arbitrary JavaScript code execution in the management UI for affected users. When a virtual host fails to start, an error message is displayed in the management UI, including the unescaped virtual host name. An attacker can exploit this by both causing a virtual host to fail and creating a new virtual host name with an XSS code snippet or changing the name of an existing one. RabbitMQ 4.0.3 and Tanzu RabbitMQ 4.0.3, as well as 3.13.8, have been released to address this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share