PT-2019-7207 · Apache+2 · Apache Activemq+2
CVSS v3.1
4.9
Média
| Vetor | AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Apache ActiveMQ client versions prior to 5.15.5
Description
A remote shutdown command in the ActiveMQConnection class was exposed, allowing an attacker logged into a compromised broker to achieve denial of service on a connected client.
Recommendations
For Apache ActiveMQ client versions prior to 5.15.5, update to version 5.15.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the ActiveMQConnection class to minimize the risk of exploitation.
Exploit
Correção
DoS
Missing Authentication
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Apache Activemq
Linuxmint
Ubuntu