logo

Database

Lack of data validation In org.apache.activemq:activemq-client

Description

Improper Input Validation and Missing Authentication for Critical Function in Apache ActiveMQ It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker logged into a compromised broker could use this flaw to achieve denial of service on a connected client.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions