Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-11775

Опубликовано: 10 сент. 2018
Источник: debian

Описание

TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vulnerable to a MITM attack between a Java application using the ActiveMQ client and the ActiveMQ server. This is now enabled by default.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
activemqfixed5.15.6-1package
activemqno-dsajessiepackage

Примечания

  • http://activemq.apache.org/security-advisories.data/CVE-2018-11775-announcement.txt

  • https://git-wip-us.apache.org/repos/asf?p=activemq.git;a=commit;h=bde7097fb8173cf871827df7811b3865679b963d

  • https://git-wip-us.apache.org/repos/asf?p=activemq.git;a=commit;h=02971a40e281713a8397d3a1809c164b594abfbb

  • Fixed in 5.15.6

Связанные уязвимости

CVSS3: 7.4
ubuntu
больше 7 лет назад

TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vulnerable to a MITM attack between a Java application using the ActiveMQ client and the ActiveMQ server. This is now enabled by default.

CVSS3: 6.8
redhat
больше 7 лет назад

TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vulnerable to a MITM attack between a Java application using the ActiveMQ client and the ActiveMQ server. This is now enabled by default.

CVSS3: 7.4
nvd
больше 7 лет назад

TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vulnerable to a MITM attack between a Java application using the ActiveMQ client and the ActiveMQ server. This is now enabled by default.

CVSS3: 7.4
github
больше 7 лет назад

Improper Certificate Validation in Apache activemq-client

CVSS3: 7.4
fstec
больше 7 лет назад

Уязвимость программной платформы Apache ActiveMQ, связанная с ошибками в настройках безопасности, позволяющая нарушителю реализовать атаку типа «человек посередине»