26437 prevent /api/* from returning text/html error messages which could act as an XSS vector (since 2.1.0) Bug 26437 allowed an attacker to create a URL to "/api/..." which would provoke an internal server error, resulting in the server returning an html page with text from the URL embedded and not escaped. This was fixed by ensuring all URLs below /api/ only ever return responses with a content type of application/json, even in the case of an internal server error. Upstream patches: http://hg.rabbitmq.com/rabbitmq-web-dispatch/rev/caf3d0a80cf3 References: https://groups.google.com/forum/#!topic/rabbitmq-users/-3Z2FyGtXhs
Created rabbitmq-server tracking bugs for this issue: Affects: fedora-all [bug 1185516] Affects: epel-all [bug 1185517]
Both this and corresponding bug 1185515 were addressed in RabbitMQ 3.4.1. We already ship ver. 3.5.x, so this issue is already fixed in Fedora 22+. As for Fedora 21 users, we strongly advise users to upgrade to F22 or to the upcoming F23.
Reopening - unfortunately it still not fixed for EPEL7.
rabbitmq-server-3.3.5-12.el7 has been pushed to the Fedora EPEL 7 stable repository. If problems still persist, please make note of it in this bug report.
This issue has been addressed in the following products: OpenStack 6 for RHEL 7 Via RHSA-2016:0308 https://rhn.redhat.com/errata/RHSA-2016-0308.html
This issue has been addressed in the following products: Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7 Via RHSA-2016:0369 https://rhn.redhat.com/errata/RHSA-2016-0369.html
This issue has been addressed in the following products: Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6 Via RHSA-2016:0368 https://rhn.redhat.com/errata/RHSA-2016-0368.html
This issue has been addressed in the following products: Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 Via RHSA-2016:0367 https://rhn.redhat.com/errata/RHSA-2016-0367.html