Lucene search

K
osvGoogleOSV:GHSA-M9W8-V359-9FFR
HistoryOct 19, 2018 - 4:42 p.m.

Improper Certificate Validation in Apache activemq-client

2018-10-1916:42:27
Google
osv.dev
38

0.004 Low

EPSS

Percentile

73.8%

TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vulnerable to a MITM attack between a Java application using the ActiveMQ client and the ActiveMQ server. This is now enabled by default.

References