QID 996902
Date Published: 2024-01-29
QID 996902: Java (Maven) Security Update for org.apache.activemq:activemq-parent (GHSA-mxf7-pv8q-294h)
Cross-site scripting (XSS) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote authenticated users to inject arbitrary web script or HTML via the JMSDestination parameter in a queue action.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-mxf7-pv8q-294h for updates and patch information.
Vendor References
- GHSA-mxf7-pv8q-294h -
github.com/advisories/GHSA-mxf7-pv8q-294h
CVEs related to QID 996902
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-mxf7-pv8q-294h | org.apache.activemq:activemq-parent |
|