PT-2018-2280 · Apache+2 · Apache Activemq+2
Publicado
2018-09-10
·
Atualizado
2024-07-23
·
CVE-2018-11775
CVSS v3.1
7.4
Alta
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Apache ActiveMQ versions prior to 5.15.6
Description
The issue is related to errors in security settings and the absence of TLS hostname verification in the Apache ActiveMQ broker. This could allow a remote attacker to implement a man-in-the-middle attack, potentially gaining unauthorized access to protected data.
Recommendations
For versions prior to 5.15.6, update to version 5.15.6 or later to enable TLS hostname verification by default. As a temporary workaround, consider configuring the Apache ActiveMQ client to enable TLS hostname verification manually until a patch is applied.
Exploit
Correção
Improper Certificate Validation
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Apache Activemq
Linuxmint
Ubuntu