Описание
It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker logged into a compromised broker could use this flaw to achieve denial of service on a connected client.
Ссылки
- Issue TrackingPatchThird Party Advisory
- PatchVendor Advisory
- Issue TrackingPatchThird Party Advisory
- PatchVendor Advisory
Уязвимые конфигурации
Одно из
Одно из
EPSS
2.7 Low
CVSS3
2.7 Low
CVSS3
4 Medium
CVSS2
Дефекты
Связанные уязвимости
It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker logged into a compromised broker could use this flaw to achieve denial of service on a connected client.
It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker logged into a compromised broker could use this flaw to achieve denial of service on a connected client.
It was found that the Apache ActiveMQ client before 5.14.5 exposed a r ...
Improper Input Validation and Missing Authentication for Critical Function in Apache ActiveMQ
EPSS
2.7 Low
CVSS3
2.7 Low
CVSS3
4 Medium
CVSS2