Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-13932

Опубликовано: 20 июл. 2020
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

In Apache ActiveMQ Artemis 2.5.0 to 2.13.0, a specially crafted MQTT packet which has an XSS payload as client-id or topic name can exploit this vulnerability. The XSS payload is being injected into the admin console's browser. The XSS payload is triggered in the diagram plugin; queue node and the info section.

A flaw was found in activemq. A specifically crafted MQTT packet which has an XSS payload as client-id or topic name can exploit this vulnerability. The XSS payload is being injected into the admin console's browser. The XSS payload is triggered in the diagram plugin; queue node and the info section.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
JBoss Developer Studio 11activemqOut of support scope
Red Hat CodeReady Studio 12activemqNot affected
Red Hat Decision Manager 7activemq-artemisNot affected
Red Hat Fuse 7activemqNot affected
Red Hat JBoss A-MQ 6activemqOut of support scope
Red Hat JBoss Data Grid 7activemq-artemisOut of support scope
Red Hat JBoss Enterprise Application Platform 7activemq-artemisNot affected
Red Hat JBoss Enterprise Application Platform Continuous Deliveryactivemq-artemisNot affected
Red Hat JBoss Fuse 6activemqOut of support scope
Red Hat JBoss Fuse Service Works 6activemqOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1858946activemq: remote XSS in web console diagram plugin

EPSS

Процентиль: 85%
0.02552
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
nvd
больше 5 лет назад

In Apache ActiveMQ Artemis 2.5.0 to 2.13.0, a specially crafted MQTT packet which has an XSS payload as client-id or topic name can exploit this vulnerability. The XSS payload is being injected into the admin console's browser. The XSS payload is triggered in the diagram plugin; queue node and the info section.

CVSS3: 6.1
github
почти 4 года назад

Cross-site Scripting (XSS) in Apache ActiveMQ Artemis

EPSS

Процентиль: 85%
0.02552
Низкий

6.5 Medium

CVSS3