Server side cross-site scripting In org.apache.activemq:activemq-client
Description
Improper Neutralization of Input During Web Page Generation in Apache ActiveMQ The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users to conduct cross-site scripting (XSS) attacks and consequently obtain sensitive information from a Java memory dump via vectors related to creating a queue.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
maven | 5.11.4, 5.12.3, 5.13.2 | ||
debian 12 | 5.13.2+dfsg-1 | ||
debian 11 | 5.13.2+dfsg-1 | ||
debian 13 | 5.13.2+dfsg-1 |
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2. 3. 4. 5. 6. 7. 8.