Lucene search

K
osvGoogleOSV:GHSA-Q9HR-3PG4-3JP4
HistoryMay 13, 2022 - 1:30 a.m.

Improper Input Validation in Apache ActiveMQ

2022-05-1301:30:05
Google
osv.dev
52
apache activemq
input validation
remote attack

EPSS

0.036

Percentile

91.9%

Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitrary code via a crafted serialized Java Message Service (JMS) ObjectMessage object.

References