activemq is vulnerable to cross-site scripting attacks. The vulnerability exists in the web based administration console on the message.jsp which allows an attacker to inject and execute malicious javascript.
CPE | Name | Operator | Version |
---|---|---|---|
activemq:sid | eq | 5.16.0-1 | |
activemq:bullseye | eq | 5.16.0-1 | |
activemq:sid | eq | 5.16.0-1 | |
activemq:bullseye | eq | 5.16.0-1 |
activemq.apache.org/security-advisories.data/CVE-2020-13947-announcement.txt
lists.apache.org/thread.html/r021c490028f61c8b6f7e38efb98e61693b0cbb6b99b02238c6fc7d66%40%3Ccommits.activemq.apache.org%3E
lists.apache.org/thread.html/r021c490028f61c8b6f7e38efb98e61693b0cbb6b99b02238c6fc7d66@%3Ccommits.activemq.apache.org%3E
lists.apache.org/thread.html/ra66791f1f2b59fa651a81cec5202acdfbf34c2154fc0ff200301cc1c%40%3Cdev.activemq.apache.org%3E
lists.apache.org/thread.html/ra66791f1f2b59fa651a81cec5202acdfbf34c2154fc0ff200301cc1c%40%3Cusers.activemq.apache.org%3E
lists.apache.org/thread.html/ra66791f1f2b59fa651a81cec5202acdfbf34c2154fc0ff200301cc1c@%3Cdev.activemq.apache.org%3E
lists.apache.org/thread.html/ra66791f1f2b59fa651a81cec5202acdfbf34c2154fc0ff200301cc1c@%3Cusers.activemq.apache.org%3E
security-tracker.debian.org/tracker/CVE-2020-13947
www.oracle.com/security-alerts/cpuApr2021.html
www.oracle.com/security-alerts/cpuoct2021.html