Updated rabbitmq-server packages that fix two security issues and one bugare now available for Red Hat Enterprise Linux OpenStack Platform 5.0(Icehouse) for RHEL 7.Red Hat Product Security has rated this update as having Moderate securityimpact.

RabbitMQ is an implementation of AMQP, the emerging standard for highperformance enterprise messaging.

The RabbitMQ server is a robust andscalable implementation of an AMQP broker.A cross-site scripting vulnerability was discovered in RabbitMQ, whichallowed using api/ path info to inject and receive data.

A remote attackercould use this flaw to create an “/api/…” URL, forcing a server errorthat resulted in the server returning an HTML page with embedded text fromthe URL (not escaped). (CVE-2014-9649)A response-splitting vulnerability was discovered in RabbitMQ.An /api/definitions URL could be specified, which then caused an arbitraryadditional header to be returned.

A remote attacker could use this flaw toinject arbitrary HTTP headers and possibly gain access to secure data.(CVE-2014-9650)This update also fixes the following bug:* Previously, if the rabbit_mirror_queue_master did not return when usingHA and ‘auto_delete’ queues, the RabbitMQ server blocked channels duringtermination.

These channels would then have no associated connections andwere displayed as ‘unknown’.

