Lucene search

K
osvGoogleOSV:CVE-2020-13932
HistoryJul 20, 2020 - 10:15 p.m.

CVE-2020-13932

2020-07-2022:15:00
Google
osv.dev
14
apache activemq
artemis
mqtt
xss
payload
vulnerability
admin console
browser
diagram plugin
queue node
info section

AI Score

5.9

Confidence

High

EPSS

0.005

Percentile

77.4%

In Apache ActiveMQ Artemis 2.5.0 to 2.13.0, a specially crafted MQTT packet which has an XSS payload as client-id or topic name can exploit this vulnerability. The XSS payload is being injected into the admin console’s browser. The XSS payload is triggered in the diagram plugin; queue node and the info section.

AI Score

5.9

Confidence

High

EPSS

0.005

Percentile

77.4%