Описание
Cross-site scripting (XSS) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote authenticated users to inject arbitrary web script or HTML via the JMSDestination parameter in a queue action.
Отчет
Not vulnerable. Apache ActiveMQ is not shipped with any supported Red Hat products.
Дополнительная информация
Статус:
Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=580882ActiveMQ: XSS in createDestination
5.5 Medium
CVSS2
Связанные уязвимости
nvd
почти 16 лет назад
Cross-site scripting (XSS) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote authenticated users to inject arbitrary web script or HTML via the JMSDestination parameter in a queue action.
5.5 Medium
CVSS2