QID 995535

Date Published: 2023-10-09

QID 995535: Java (Maven) Security Update for org.apache.activemq:apollo-project (GHSA-wmhw-hpwh-44pg)

XML external entity (XXE) vulnerability in Apache ActiveMQ Apollo 1.x before 1.7.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Refer to Github security advisory GHSA-wmhw-hpwh-44pg for updates and patch information.
    Vendor References

    CVEs related to QID 995535

    Software Advisories
    Advisory ID Software Component Link
    GHSA-wmhw-hpwh-44pg org.apache.activemq:apollo-project URL Logo github.com/advisories/GHSA-wmhw-hpwh-44pg