You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@activemq.apache.org by Jean-Baptiste Onofre <jb...@nanthrax.net> on 2020/05/14 05:24:16 UTC

[CVE-2020-1941] XSS in ActiveMQ WebConsole

[CVE-2020-1941] XSS in WebConsole

Severity: Medium

Vendor:
The Apache Software Foundation

Versions Affected:
Apache ActiveMQ 5.0.0 - 5.15.11

Description:
The webconsole admin GUI is open to XSS, in the view that lists the contents of a queue.

Mitigation:
Upgrade to Apache ActiveMQ 5.15.12. 

Credit:
This issue was discovered by:

* Przemysław Kowalski <pr...@stmsolutions.pl>


[CVE-2020-1941] XSS in ActiveMQ WebConsole

Posted by Jean-Baptiste Onofre <jb...@nanthrax.net>.
[CVE-2020-1941] XSS in WebConsole

Severity: Medium

Vendor:
The Apache Software Foundation

Versions Affected:
Apache ActiveMQ 5.0.0 - 5.15.11

Description:
The webconsole admin GUI is open to XSS, in the view that lists the contents of a queue.

Mitigation:
Upgrade to Apache ActiveMQ 5.15.12. 

Credit:
This issue was discovered by:

* Przemysław Kowalski <przemyslawk@stmsolutions.pl <ma...@stmsolutions.pl>>