QID 981677
QID 981677: Java (maven) Security Update for org.apache.activemq:activemq-client (GHSA-jvpp-hxjj-5ccc)
It was found that the Apache ActiveMQ client before 5.15.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker logged into a compromised broker could use this flaw to achieve denial of service on a connected client.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-jvpp-hxjj-5ccc for updates pertaining to this vulnerability.
Vendor References
- GHSA-jvpp-hxjj-5ccc -
github.com/advisories/GHSA-jvpp-hxjj-5ccc
CVEs related to QID 981677
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-jvpp-hxjj-5ccc | org.apache.activemq:activemq-client |
|