Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cv6r-h2fm-pvrp

Опубликовано: 24 авг. 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

HTML Injection in ActiveMQ Artemis Web Console

In Apache ActiveMQ Artemis prior to 2.24.0, an attacker could show malicious content and/or redirect users to a malicious URL in the web console by using HTML in the name of an address or queue.

Пакеты

Наименование

org.apache.activemq:artemis-server

maven
Затронутые версииВерсия исправления

< 2.24.0

2.24.0

EPSS

Процентиль: 92%
0.07498
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79
CWE-80

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 3 лет назад

In Apache ActiveMQ Artemis prior to 2.24.0, an attacker could show malicious content and/or redirect users to a malicious URL in the web console by using HTML in the name of an address or queue.

CVSS3: 6.1
redhat
больше 3 лет назад

In Apache ActiveMQ Artemis prior to 2.24.0, an attacker could show malicious content and/or redirect users to a malicious URL in the web console by using HTML in the name of an address or queue.

CVSS3: 6.1
nvd
больше 3 лет назад

In Apache ActiveMQ Artemis prior to 2.24.0, an attacker could show malicious content and/or redirect users to a malicious URL in the web console by using HTML in the name of an address or queue.

EPSS

Процентиль: 92%
0.07498
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79
CWE-80