VDB
EN
MEDIUM 6.1

GHSA-3h2h-xqr2-2jp7

Cross-site Scripting (XSS) in Apache ActiveMQ Artemis

상세

In Apache ActiveMQ Artemis 2.5.0 to 2.13.0, a specially crafted MQTT packet which has an XSS payload as client-id or topic name can exploit this vulnerability. The XSS payload is being injected into the admin console's browser. The XSS payload is triggered in the diagram plugin; queue node and the info section.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

Maven / org.apache.activemq:apache-artemis
최초 영향 버전: 2.5.0 수정 버전: 2.14.0
수정 # pom.xml: bump <version>2.14.0</version> for org.apache.activemq:apache-artemis

참고