Lack of data validation In org.apache.activemq:activemq-client
Description
Improper Input Validation in Apache ActiveMQ Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitrary code via a crafted serialized Java Message Service (JMS) ObjectMessage object.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
maven | 5.11.3, 5.12.2 | ||
debian 13 | 5.13.2+dfsg-1 | ||
debian 12 | 5.13.2+dfsg-1 | ||
debian 11 | 5.13.2+dfsg-1 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13. 14. 15. 16. 17. 18. 19.