Database/Control plane, storage & DevOps
RabbitMQ: Unsanitized username rendered in the management UI
CVSS 3.1CVE-2021-32718Control plane, storage & DevOpscurated
Impact
Unsanitized username rendered in the management UI -> stored XSS against an admin
Who can reach it
Network (remote)
What to do
Control-plane: management plugin upgrade; keep the UI off the public internet
References
Related entries
- RabbitMQ: HTTP API enforces no request body limitCVE-2023-46118 · RabbitMQMedium
- etcd: LeaseTimeToLive exposes key names to a user without read permission on those keysCVE-2023-32082 · etcdLow
- Prometheus / Thanos (golang-jwt): Unclear ParseWithClaims error behaviorCVE-2024-51744 · Prometheus / Thanos (golang-jwt)Low
- GitLab: a developer removed from a project can still push commits via merge request collaboration settingsCVE-2025-14562 · GitLab CE/EE (merge request collaboration authorization)Low
- Inspektor Gadget: malformed ELF crashes or exhausts memory in the privileged eBPF tracerCVE-2026-44778 · Inspektor Gadget uprobetracer USDT note parser (pkg/uprobetracer/usdt.go)Low
- Jenkins: project naming strategy config lets Overall/Manage holders instantiate admin-only typesCVE-2026-70430 · Jenkins core (project naming strategy configuration)Low
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.