Описание
An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the message.jsp page of Apache ActiveMQ versions 5.15.12 through 5.16.0.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| activemq | fixed | 5.16.1-1 | package |
Примечания
Admin console not enabled in the Debian package, see #702670)
https://activemq.apache.org/security-advisories.data/CVE-2020-13947-announcement.txt
Fixed in 5.15.13, 5.16.1
EPSS
Связанные уязвимости
An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the message.jsp page of Apache ActiveMQ versions 5.15.12 through 5.16.0.
An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the message.jsp page of Apache ActiveMQ versions 5.15.12 through 5.16.0.
Уязвимость сценария message.jsp веб-консоли администрирования программной платформы Apache ActiveMQ, позволяющая нарушителю проводить межсайтовые сценарные атаки
EPSS