activemq: Cross-site scripting in webconsole admin GUI
Published May 14, 2020
7.3
HIGHCVSS 3.1
EPSS 7.15%
Description
In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in the view that lists the contents of a queue.
Affected products
- Vendor n/a Product Apache ActiveMQ Defaultn/a
- Version Apache ActiveMQ 5.0.0 to 5.15.11StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Apache ActiveMQ | n/a |
|
Configuration 2
- ≥ 8.0.0 · ≤ 8.2.2
- 8.1.1
- 8.2.0
- 8.2.1
- 8.1.1
- 8.2.0
- 8.2.1
- 8.1.1
- 8.2.0
- 8.2.1
- 11.1.1.7.0
- 12.0.0
- 12.1.0
No data.
JBoss Developer Studio 11
activemq
Out of support scope
Red Hat AMQ Broker 7
mqtt-client
Not affected
Red Hat Decision Manager 7
activemq-artemis
Not affected
Red Hat Fuse 7
activemq
Not affected
Red Hat JBoss A-MQ 6
activemq
Out of support scope
Red Hat JBoss Data Grid 7
activemq-artemis
Out of support scope
Red Hat JBoss Enterprise Application Platform 7
activemq-artemis
Not affected
Red Hat JBoss Fuse 6
activemq
Out of support scope
Red Hat JBoss Fuse Service Works 6
activemq
Out of support scope
Red Hat Process Automation 7
activemq-artemis
Not affected
Red Hat Single Sign-On 7
activemq-artemis
Not affected
Red Hat Virtualization 4
eap7-activemq-artemis
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| JBoss Developer Studio 11 | activemq | Out of support scope | n/a |
| Red Hat AMQ Broker 7 | mqtt-client | Not affected | n/a |
| Red Hat Decision Manager 7 | activemq-artemis | Not affected | n/a |
| Red Hat Fuse 7 | activemq | Not affected | n/a |
| Red Hat JBoss A-MQ 6 | activemq | Out of support scope | n/a |
| Red Hat JBoss Data Grid 7 | activemq-artemis | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | activemq-artemis | Not affected | n/a |
| Red Hat JBoss Fuse 6 | activemq | Out of support scope | n/a |
| Red Hat JBoss Fuse Service Works 6 | activemq | Out of support scope | n/a |
| Red Hat Process Automation 7 | activemq-artemis | Not affected | n/a |
| Red Hat Single Sign-On 7 | activemq-artemis | Not affected | n/a |
| Red Hat Virtualization 4 | eap7-activemq-artemis | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (21)
- http://activemq.apache.org/security-advisories.data/CVE-2020-1941-announcement.txt x_refsource_MISCVendor Advisory
- https://access.redhat.com/security/cve/CVE-2020-1941 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1848045 Issue Tracking
- https://github.com/advisories/GHSA-cc94-3v9c-7rm8 Advisory
- https://github.com/apache/activemq/commit/7793a95
- https://github.com/apache/activemq/commit/81bd743eaa243f0cc5dfbb1342cee1fef1fc5df2
- https://github.com/apache/activemq/commit/c0e17a3
- https://issues.apache.org/jira/browse/AMQ-7231
- https://lists.apache.org/thread.html/r946488fb942fd35c6a6e0359f52504a558ed438574a8f14d36d7dcd7%40%3Ccommits.activemq.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r946488fb942fd35c6a6e0359f52504a558ed438574a8f14d36d7dcd7@%3Ccommits.activemq.apache.org%3E
- https://lists.apache.org/thread.html/rb2fd3bf2dce042e0ab3f3c94c4767c96bb2e7e6737624d63162df36d%40%3Ccommits.activemq.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rb2fd3bf2dce042e0ab3f3c94c4767c96bb2e7e6737624d63162df36d@%3Ccommits.activemq.apache.org%3E
- https://lists.apache.org/thread.html/re4672802b0e5ed67c08c9e77057d52138e062f77cc09581b723cf95a%40%3Ccommits.activemq.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/re4672802b0e5ed67c08c9e77057d52138e062f77cc09581b723cf95a@%3Ccommits.activemq.apache.org%3E
- https://nvd.nist.gov/vuln/detail/CVE-2020-1941
- https://www.cve.org/CVERecord?id=CVE-2020-1941
- https://www.oracle.com//security-alerts/cpujul2021.html x_refsource_MISCThird Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.html x_refsource_MISCThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2020.html x_refsource_MISCThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2021.html
- https://www.oracle.com/security-alerts/cpuoct2020.html x_refsource_MISCThird Party Advisory
Change history (0)
No recorded changes yet.