Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m9w8-v359-9ffr

Опубликовано: 19 окт. 2018
Источник: github
Github: Прошло ревью
CVSS3: 7.4

Описание

Improper Certificate Validation in Apache activemq-client

TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vulnerable to a MITM attack between a Java application using the ActiveMQ client and the ActiveMQ server. This is now enabled by default.

Пакеты

Наименование

org.apache.activemq:activemq-client

maven
Затронутые версииВерсия исправления

< 5.15.6

5.15.6

EPSS

Процентиль: 65%
0.00492
Низкий

7.4 High

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 7.4
ubuntu
больше 7 лет назад

TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vulnerable to a MITM attack between a Java application using the ActiveMQ client and the ActiveMQ server. This is now enabled by default.

CVSS3: 6.8
redhat
больше 7 лет назад

TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vulnerable to a MITM attack between a Java application using the ActiveMQ client and the ActiveMQ server. This is now enabled by default.

CVSS3: 7.4
nvd
больше 7 лет назад

TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vulnerable to a MITM attack between a Java application using the ActiveMQ client and the ActiveMQ server. This is now enabled by default.

CVSS3: 7.4
debian
больше 7 лет назад

TLS hostname verification when using the Apache ActiveMQ Client before ...

CVSS3: 7.4
fstec
больше 7 лет назад

Уязвимость программной платформы Apache ActiveMQ, связанная с ошибками в настройках безопасности, позволяющая нарушителю реализовать атаку типа «человек посередине»

EPSS

Процентиль: 65%
0.00492
Низкий

7.4 High

CVSS3

Дефекты

CWE-295