QID 997361
Date Published: 2024-02-20
QID 997361: Java (Maven) Security Update for org.apache.activemq:activemq-web-console (GHSA-v2c9-9m8v-8jjm)
The Jetty ResourceHandler in Apache ActiveMQ 5.x before 5.3.2 and 5.4.x before 5.4.0 allows remote attackers to read JSP source code via a // (slash slash) initial substring in a URI for (1) admin/index.jsp, (2) admin/queues.jsp, or (3) admin/topics.jsp.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-v2c9-9m8v-8jjm for updates and patch information.
Vendor References
- GHSA-v2c9-9m8v-8jjm -
github.com/advisories/GHSA-v2c9-9m8v-8jjm
CVEs related to QID 997361
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-v2c9-9m8v-8jjm | org.apache.activemq:activemq-web-console |
|