PT-2021-9682 · Apache · Apache Activemq

Published

2021-02-08

·

Updated

2024-03-06

·

CVE-2020-13947

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Apache ActiveMQ versions 5.15.12 through 5.16.0
Description A cross-site scripting issue was found in the web-based administration console, specifically on the message.jsp page.
Recommendations For Apache ActiveMQ versions 5.15.12 through 5.16.0, consider restricting access to the message.jsp page until a fix is available. As a temporary workaround, avoid using the administration console's web-based interface for sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

BDU:2025-01883
BIT-ACTIVEMQ-2020-13947
CVE-2020-13947
GHSA-66GW-CH5V-74V8

Affected Products

Apache Activemq