Описание
The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users to conduct cross-site scripting (XSS) attacks and consequently obtain sensitive information from a Java memory dump via vectors related to creating a queue.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | code disabled |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was not-affected [code disabled]] |
| precise | not-affected | code disabled |
| trusty | not-affected | code disabled |
| trusty/esm | DNE | trusty was not-affected [code disabled] |
| upstream | needs-triage | |
| vivid/stable-phone-overlay | DNE | |
| vivid/ubuntu-core | DNE | |
| wily | not-affected | code disabled |
Показывать по
EPSS
3.5 Low
CVSS2
5.4 Medium
CVSS3
Связанные уязвимости
The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users to conduct cross-site scripting (XSS) attacks and consequently obtain sensitive information from a Java memory dump via vectors related to creating a queue.
The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users to conduct cross-site scripting (XSS) attacks and consequently obtain sensitive information from a Java memory dump via vectors related to creating a queue.
The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5 ...
Improper Neutralization of Input During Web Page Generation in Apache ActiveMQ
EPSS
3.5 Low
CVSS2
5.4 Medium
CVSS3