PT-2018-2280 · Apache+2 · Apache Activemq+2

Published

2018-09-10

·

Updated

2024-07-23

·

CVE-2018-11775

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache ActiveMQ versions prior to 5.15.6
Description The issue is related to errors in security settings and the absence of TLS hostname verification in the Apache ActiveMQ broker. This could allow a remote attacker to implement a man-in-the-middle attack, potentially gaining unauthorized access to protected data.
Recommendations For versions prior to 5.15.6, update to version 5.15.6 or later to enable TLS hostname verification by default. As a temporary workaround, consider configuring the Apache ActiveMQ client to enable TLS hostname verification manually until a patch is applied.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-00382
BDU:2019-01768
CVE-2018-11775
DLA-2583-1
GHSA-M9W8-V359-9FFR
USN-6910-1

Affected Products

Apache Activemq
Linuxmint
Ubuntu