Skip to content

Commit 7ee00c7

Browse files
committed
Patch rabbitmq-server for CVE-2025-30219 [Medium] (#13200)
(cherry picked from commit b7f1d7c)
1 parent 894c58f commit 7ee00c7

2 files changed

Lines changed: 30 additions & 1 deletion

File tree

Lines changed: 25 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,25 @@
1+
From 3d88ed83db8f981006559ee805ba7a1ffded60d5 Mon Sep 17 00:00:00 2001
2+
From: Michael Klishin <michael@clojurewerkz.org>
3+
Date: Fri, 25 Oct 2024 22:14:41 -0400
4+
Subject: [PATCH] Use fmt_string in this error message
5+
6+
---
7+
deps/rabbitmq_management/priv/www/js/tmpl/overview.ejs | 2 +-
8+
1 file changed, 1 insertion(+), 1 deletion(-)
9+
10+
diff --git a/deps/rabbitmq_management/priv/www/js/tmpl/overview.ejs b/deps/rabbitmq_management/priv/www/js/tmpl/overview.ejs
11+
index 769c6d7..8c6f0c3 100644
12+
--- a/deps/rabbitmq_management/priv/www/js/tmpl/overview.ejs
13+
+++ b/deps/rabbitmq_management/priv/www/js/tmpl/overview.ejs
14+
@@ -27,7 +27,7 @@
15+
if (vhosts[i].cluster_state[vhost_status_node] != 'running') {
16+
%>
17+
<p class="warning">
18+
- Virtual host <b><%= vhosts[i].name %></b> experienced an error on node <b><%= vhost_status_node %></b> and may be inaccessible
19+
+ Virtual host <b><%= fmt_string(vhosts[i].name) %></b> experienced an error on node <b><%= fmt_string(vhost_status_node) %></b> and may be inaccessible
20+
</p>
21+
<% }}} %>
22+
</div>
23+
--
24+
2.34.1
25+

SPECS/rabbitmq-server/rabbitmq-server.spec

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
Summary: rabbitmq-server
33
Name: rabbitmq-server
44
Version: 3.11.24
5-
Release: 2%{?dist}
5+
Release: 3%{?dist}
66
License: Apache-2.0 and MPL 2.0
77
Vendor: Microsoft Corporation
88
Distribution: Mariner
@@ -30,6 +30,7 @@ Source3: rabbitmq-server-hex-cache-%{version}.tar.gz
3030
# 8. Run `tar -czf rabbitmq-server-hex-cache-<version>.tar.gz cache.erl`
3131
# --------
3232
Patch0: CVE-2023-50966.patch
33+
Patch1: CVE-2025-30219.patch
3334
BuildRequires: erlang
3435
BuildRequires: elixir
3536
BuildRequires: libxslt
@@ -115,6 +116,9 @@ done
115116
%{_libdir}/rabbitmq/lib/rabbitmq_server-%{version}/*
116117

117118
%changelog
119+
* Mon Mar 31 2025 Ankita Pareek <ankitapareek@microsoft.com> - 3.11.24-3
120+
- Add patch for CVE-2025-30219
121+
118122
* Thu Feb 13 2024 Kanishk Bansal <kanbansal@microsoft.com> - 3.11.24-2
119123
- Add patch for CVE-2023-50966
120124

0 commit comments

Comments
 (0)