Lucene search

K
githubGitHub Advisory DatabaseGHSA-34FP-XVXP-RG22
HistoryMay 17, 2022 - 3:46 a.m.

Apache ActiveMQ default configuration subject to denial of service

2022-05-1703:46:32
CWE-400
GitHub Advisory Database
github.com
11
apache activemq
default configuration
denial of service
http requests
remote attackers

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.005

Percentile

76.8%

The default configuration of Apache ActiveMQ before 5.8.0 enables a sample web application, which allows remote attackers to cause a denial of service (broker resource consumption) via HTTP requests.

Affected configurations

Vulners
Node
org.apache.activemq\activemqMatchcore
OR
org.apache.activemq\apacheMatchactivemq
VendorProductVersionCPE
org.apache.activemq\activemqcorecpe:2.3:a:org.apache.activemq\:activemq:core:*:*:*:*:*:*:*:*
org.apache.activemq\apacheactivemqcpe:2.3:a:org.apache.activemq\:apache:activemq:*:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.005

Percentile

76.8%