VDB
Sign up
CRITICAL9.8

GHSA-rxqh-fc23-gxp2

Improper Input Validation in Apache ActiveMQ

Quick fix

GHSA-rxqh-fc23-gxp2 — org.apache.activemq:activemq-client: upgrade to the fixed version with the command below.

# pom.xml: bump <version>5.14.0</version> for org.apache.activemq:activemq-client

Details

The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.apache.activemq:activemq-client
Introduced in: 5.0.0Fixed in: 5.14.0
Fix# pom.xml: bump <version>5.14.0</version> for org.apache.activemq:activemq-client

References