PT-2018-2280 · Apache+2 · Apache Activemq+2
Published
2018-09-10
·
Updated
2024-07-23
·
CVE-2018-11775
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Apache ActiveMQ versions prior to 5.15.6
Description
The issue is related to errors in security settings and the absence of TLS hostname verification in the Apache ActiveMQ broker. This could allow a remote attacker to implement a man-in-the-middle attack, potentially gaining unauthorized access to protected data.
Recommendations
For versions prior to 5.15.6, update to version 5.15.6 or later to enable TLS hostname verification by default. As a temporary workaround, consider configuring the Apache ActiveMQ client to enable TLS hostname verification manually until a patch is applied.
Exploit
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Activemq
Linuxmint
Ubuntu