Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41043

Опубликовано: 24 апр. 2026
Источник: redhat
CVSS3: 4.6
EPSS Низкий

Описание

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache ActiveMQ, Apache ActiveMQ Web. An authenticated attacker can show malicious content when browsing queues in the web console by overriding the content type to be HTML (instead of XML) and by injecting HTML into a JMS selector field. This issue affects Apache ActiveMQ: before 5.19.6, from 6.0.0 before 6.2.5; Apache ActiveMQ Web: before 5.19.6, from 6.0.0 before 6.2.5. Users are recommended to upgrade to version 6.2.5 or 5.19.6, which fixes the issue.

A flaw was found in Apache ActiveMQ and Apache ActiveMQ Web. An authenticated attacker can exploit a Cross-Site Scripting (XSS) vulnerability by injecting malicious HTML into a Java Message Service (JMS) selector field and overriding the content type to HTML. This allows the attacker to display malicious content to other users browsing queues in the web console, potentially leading to information disclosure or execution of arbitrary client-side scripts.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AMQ Broker 7activemq-clientFix deferred
Red Hat build of Apache Camel for Spring Boot 4activemq-clientFix deferred
Red Hat build of Apache Camel for Spring Boot 4activemq-client-jakartaFix deferred
Red Hat Data Grid 8activemq-clientFix deferred
Red Hat Fuse 7activemq-allFix deferred
Red Hat Fuse 7activemq-clientFix deferred
Red Hat Fuse 7activemq-webFix deferred
Red Hat JBoss Enterprise Application Platform 7activemq-clientFix deferred
Red Hat JBoss Enterprise Application Platform 8activemq-clientFix deferred
Red Hat JBoss Enterprise Application Platform 8activemq-client-jakartaFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2461407Apache ActiveMQ: Apache ActiveMQ Web: Apache ActiveMQ: Information disclosure via Cross-Site Scripting in web console

EPSS

Процентиль: 43%
0.0056
Низкий

4.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
3 месяца назад

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache ActiveMQ, Apache ActiveMQ Web. An authenticated attacker can show malicious content when browsing queues in the web console by overriding the content type to be HTML (instead of XML) and by injecting HTML into a JMS selector field. This issue affects Apache ActiveMQ: before 5.19.6, from 6.0.0 before 6.2.5; Apache ActiveMQ Web: before 5.19.6, from 6.0.0 before 6.2.5. Users are recommended to upgrade to version 6.2.5 or 5.19.6, which fixes the issue.

CVSS3: 6.5
nvd
3 месяца назад

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache ActiveMQ, Apache ActiveMQ Web. An authenticated attacker can show malicious content when browsing queues in the web console by overriding the content type to be HTML (instead of XML) and by injecting HTML into a JMS selector field. This issue affects Apache ActiveMQ: before 5.19.6, from 6.0.0 before 6.2.5; Apache ActiveMQ Web: before 5.19.6, from 6.0.0 before 6.2.5. Users are recommended to upgrade to version 6.2.5 or 5.19.6, which fixes the issue.

CVSS3: 6.5
debian
3 месяца назад

Improper Neutralization of Script-Related HTML Tags in a Web Page (Bas ...

CVSS3: 6.5
redos
4 дня назад

Уязвимость apache-activemq

CVSS3: 6.5
github
3 месяца назад

Apache ActiveMQ Vulnerable to Cross-site Scripting

EPSS

Процентиль: 43%
0.0056
Низкий

4.6 Medium

CVSS3