VDB
Sign up
MEDIUM6.5

GHSA-2jp3-2923-9h52

Apache ActiveMQ Vulnerable to Cross-site Scripting

Quick fix

GHSA-2jp3-2923-9h52 — org.apache.activemq:apache-activemq: upgrade to the fixed version with the command below.

# pom.xml: bump <version>5.19.6</version> for org.apache.activemq:apache-activemq

Details

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache ActiveMQ, Apache ActiveMQ Web.

An authenticated attacker can show malicious content when browsing queues in the web console by overriding the content type to be HTML (instead of XML) and by injecting HTML into a JMS selector field.

This issue affects Apache ActiveMQ: before 5.19.6, from 6.0.0 before 6.2.5; Apache ActiveMQ Web: before 5.19.6, from 6.0.0 before 6.2.5.

Users are recommended to upgrade to version 6.2.5 or 5.19.6, which fixes the issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.apache.activemq:apache-activemq
Introduced in: 0Fixed in: 5.19.6
Fix# pom.xml: bump <version>5.19.6</version> for org.apache.activemq:apache-activemq
Maven/org.apache.activemq:activemq-all
Introduced in: 0Fixed in: 5.19.6
Fix# pom.xml: bump <version>5.19.6</version> for org.apache.activemq:activemq-all
Maven/org.apache.activemq:activemq-broker
Introduced in: 0Fixed in: 5.19.6
Fix# pom.xml: bump <version>5.19.6</version> for org.apache.activemq:activemq-broker
Maven/org.apache.activemq:apache-activemq
Introduced in: 6.0.0Fixed in: 6.2.5
Fix# pom.xml: bump <version>6.2.5</version> for org.apache.activemq:apache-activemq
Maven/org.apache.activemq:activemq-all
Introduced in: 6.0.0Fixed in: 6.2.5
Fix# pom.xml: bump <version>6.2.5</version> for org.apache.activemq:activemq-all
Maven/org.apache.activemq:activemq-broker
Introduced in: 6.0.0Fixed in: 6.2.5
Fix# pom.xml: bump <version>6.2.5</version> for org.apache.activemq:activemq-broker

References