Описание
Improper Neutralization of Input During Web Page Generation in Apache ActiveMQ
The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users to conduct cross-site scripting (XSS) attacks and consequently obtain sensitive information from a Java memory dump via vectors related to creating a queue.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2016-0782
- https://github.com/apache/activemq/commit/0c9fdb5b4180c1ae800bbc8bae7a2c0620f6749b
- https://github.com/apache/activemq/commit/2061186a0a2486aebf26c4ceb8126933ed01826e
- https://github.com/apache/activemq/commit/7828069637acb2f1ca1710523f6a2b216c12c7f8
- https://access.redhat.com/errata/RHSA-2016:1424
- https://bugzilla.redhat.com/show_bug.cgi?id=1317516
- https://github.com/apache/activemq/compare/activemq-5.13.1...activemq-5.13.2
- https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2@%3Ccommits.activemq.apache.org%3E
- http://activemq.apache.org/security-advisories.data/CVE-2016-0782-announcement.txt
- http://packetstormsecurity.com/files/136215/Apache-ActiveMQ-5.13.0-Cross-Site-Scripting.html
Пакеты
org.apache.activemq:activemq-client
>= 5.0.0, <= 5.11.3
5.11.4
org.apache.activemq:activemq-client
>= 5.12.0, <= 5.12.2
5.12.3
org.apache.activemq:activemq-client
>= 5.13.0, <= 5.13.1
5.13.2
Связанные уязвимости
The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users to conduct cross-site scripting (XSS) attacks and consequently obtain sensitive information from a Java memory dump via vectors related to creating a queue.
The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users to conduct cross-site scripting (XSS) attacks and consequently obtain sensitive information from a Java memory dump via vectors related to creating a queue.
The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users to conduct cross-site scripting (XSS) attacks and consequently obtain sensitive information from a Java memory dump via vectors related to creating a queue.
The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5 ...