Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7qm4-p377-fr2r

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 3.7

Описание

ActiveMQ's OpenWire protocol exposes certain system details as plain text

When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was found that certain system details (such as the OS and kernel version) are exposed as plain text.

Пакеты

Наименование

org.apache.activemq:activemq-openwire-generator

maven
Затронутые версииВерсия исправления

>= 5.14.0, < 5.15.3

5.15.3

Наименование

org.apache.activemq:activemq-parent

maven
Затронутые версииВерсия исправления

>= 5.15.0, < 5.15.3

5.15.3

Наименование

org.apache.activemq:activemq-parent

maven
Затронутые версииВерсия исправления

>= 5.14.0, < 5.14.6

5.14.6

EPSS

Процентиль: 98%
0.65728
Средний

3.7 Low

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 3.7
ubuntu
почти 8 лет назад

When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was found that certain system details (such as the OS and kernel version) are exposed as plain text.

CVSS3: 3.5
redhat
почти 8 лет назад

When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was found that certain system details (such as the OS and kernel version) are exposed as plain text.

CVSS3: 3.7
nvd
почти 8 лет назад

When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was found that certain system details (such as the OS and kernel version) are exposed as plain text.

CVSS3: 3.7
debian
почти 8 лет назад

When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 ...

EPSS

Процентиль: 98%
0.65728
Средний

3.7 Low

CVSS3

Дефекты

CWE-200