CVE-2010-1244
Summary
| CVE | CVE-2010-1244 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-04-05 16:30:00 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Cross-site request forgery (CSRF) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote attackers to hijack the authentication of unspecified victims for requests that create queues via the JMSDestination parameter in a queue action. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Activemq | 1.1 | All | All | All |
| Application | Apache | Activemq | 1.2 | All | All | All |
| Application | Apache | Activemq | 1.3 | All | All | All |
| Application | Apache | Activemq | 1.4 | All | All | All |
| Application | Apache | Activemq | 1.5 | All | All | All |
| Application | Apache | Activemq | 2.0 | All | All | All |
| Application | Apache | Activemq | 2.1 | All | All | All |
| Application | Apache | Activemq | 3.0 | All | All | All |
| Application | Apache | Activemq | 3.1 | All | All | All |
| Application | Apache | Activemq | 3.2 | All | All | All |
| Application | Apache | Activemq | 3.2.1 | All | All | All |
| Application | Apache | Activemq | 3.2.2 | All | All | All |
| Application | Apache | Activemq | 4.0 | All | All | All |
| Application | Apache | Activemq | 4.0 | m4 | All | All |
| Application | Apache | Activemq | 4.0 | rc2 | All | All |
| Application | Apache | Activemq | 4.0.1 | All | All | All |
| Application | Apache | Activemq | 4.0.2 | All | All | All |
| Application | Apache | Activemq | 4.1.0 | All | All | All |
| Application | Apache | Activemq | 4.1.1 | All | All | All |
| Application | Apache | Activemq | 5.0.0 | All | All | All |
| Application | Apache | Activemq | 5.1.0 | All | All | All |
| Application | Apache | Activemq | 5.2.0 | All | All | All |
| Application | Apache | Activemq | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 404 Not Found | af854a3a-2127-422b-91ae-364da2661108 | issues.apache.org | Exploit |
| Apache ActiveMQ Script Insertion and Cross-Site Request Forgery - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Apache ActiveMQ -- ActiveMQ 5.3.1 Release | af854a3a-2127-422b-91ae-364da2661108 | activemq.apache.org | Patch |
| 404 Not Found | af854a3a-2127-422b-91ae-364da2661108 | issues.apache.org | Exploit |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 996944 Java (Maven) Security Update for org.apache.activemq:activemq-parent (GHSA-33j4-8vcr-f79v)