Insecure digital certificates In org.apache.activemq:activemq-client
Description
Improper Certificate Validation in Apache activemq-client TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vulnerable to a MITM attack between a Java application using the ActiveMQ client and the ActiveMQ server. This is now enabled by default.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
maven | 5.15.6 | ||
debian 11 | 5.15.6-1 | ||
debian 12 | 5.15.6-1 | ||
debian 13 | 5.15.6-1 |
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9.
References
1. 2. 3. 4. 5. 6. 7. 8. 9.