Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jvpp-hxjj-5ccc

Опубликовано: 01 авг. 2019
Источник: github
Github: Прошло ревью
CVSS3: 4.9

Описание

Improper Input Validation and Missing Authentication for Critical Function in Apache ActiveMQ

It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker logged into a compromised broker could use this flaw to achieve denial of service on a connected client.

Пакеты

Наименование

org.apache.activemq:activemq-client

maven
Затронутые версииВерсия исправления

< 5.14.5

5.14.5

EPSS

Процентиль: 24%
0.00082
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-20
CWE-306

Связанные уязвимости

CVSS3: 2.7
ubuntu
больше 6 лет назад

It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker logged into a compromised broker could use this flaw to achieve denial of service on a connected client.

CVSS3: 2.7
redhat
почти 9 лет назад

It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker logged into a compromised broker could use this flaw to achieve denial of service on a connected client.

CVSS3: 2.7
nvd
больше 6 лет назад

It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker logged into a compromised broker could use this flaw to achieve denial of service on a connected client.

CVSS3: 2.7
debian
больше 6 лет назад

It was found that the Apache ActiveMQ client before 5.14.5 exposed a r ...

EPSS

Процентиль: 24%
0.00082
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-20
CWE-306