You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@activemq.apache.org by "Albert Baker (JIRA)" <ji...@apache.org> on 2018/07/26 22:10:00 UTC

[jira] [Reopened] (AMQ-7019) ActiveMQ 5.15.4 jolokia.jar which has one high severity CVE against it.

     [ https://issues.apache.org/jira/browse/AMQ-7019?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Albert Baker reopened AMQ-7019:
-------------------------------

Doesnt matter that AMQ is not ActiveMQ.  Jolokia is jalokia and is in both projects. Jalokia is the problem. Re-Open the issue, and fix the real issue. Jalokia is the issue.  Update the ActiveMQ pom.xml to point to the newer version of Jalokia that is fixed.   If no new/fixed version of jalokia exists, keep the ticket open.

> ActiveMQ 5.15.4 jolokia.jar which has one high severity CVE against it.
> -----------------------------------------------------------------------
>
>                 Key: AMQ-7019
>                 URL: https://issues.apache.org/jira/browse/AMQ-7019
>             Project: ActiveMQ
>          Issue Type: Bug
>          Components: webconsole
>    Affects Versions: 5.15.4
>         Environment: Customer environment is a mix of Linux and Windows, Gig-LAN (Medical & Finacial services).  Will not accept the risk of having even one high severity CVE in thier environment. The cost of (SOX/HIPPA) insurence is too high to allow even one CVE with newly deployed systems.
>            Reporter: Albert Baker
>            Priority: Blocker
>
> ActiveMQ 5.15.4 jolokia.jar which has one high severity CVE against it.
> Discovered by adding OWASP Dependency check into ActiveMQ pom.xml and running the OWASP report.
> CVE-2015-5182 Severity:High  CVSS Score: 6.8 
> allows Cross-site request forgery (CSRF) vulnerability in the jolokia API in A-MQ. 
> CONFIRM - https://bugzilla.redhat.com/show_bug.cgi?id=1248809 CONFIRM



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)