Lack of data validation In org.apache.activemq:activemq-client
Description
Improper Input Validation and Missing Authentication for Critical Function in Apache ActiveMQ It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker logged into a compromised broker could use this flaw to achieve denial of service on a connected client.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
maven | 5.14.5 | ||
debian 12 | 5.14.3-3 | ||
debian 13 | 5.14.3-3 | ||
debian 11 | 5.14.3-3 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3.