PT-2018-2280 · Apache+2 · Apache Activemq+2

Publicado

2018-09-10

·

Atualizado

2024-07-23

·

CVE-2018-11775

CVSS v3.1

7.4

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache ActiveMQ versions prior to 5.15.6
Description The issue is related to errors in security settings and the absence of TLS hostname verification in the Apache ActiveMQ broker. This could allow a remote attacker to implement a man-in-the-middle attack, potentially gaining unauthorized access to protected data.
Recommendations For versions prior to 5.15.6, update to version 5.15.6 or later to enable TLS hostname verification by default. As a temporary workaround, consider configuring the Apache ActiveMQ client to enable TLS hostname verification manually until a patch is applied.

Exploit

Correção

Improper Certificate Validation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-00382
BDU:2019-01768
CVE-2018-11775
DLA-2583-1
GHSA-M9W8-V359-9FFR
USN-6910-1

Produtos afetados

Apache Activemq
Linuxmint
Ubuntu