org.apache.activemq:activemq-parent
Maven7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.apache.activemq:activemq-parentpage 1 of 1
- CVE-2010-0684NONECVSS 0.0EG 0.0✓ Fixed in 5.3.12010-04-05
vulnerable: 4.1.1 ... 5.3.0 (6 versions)
Cross-site scripting (XSS) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote authenticated users to inject arbitrary web script or HTML via the JMSDestination parameter in a queue action.
- CVE-2010-1244NONECVSS 0.0EG 0.0✓ Fixed in 5.3.12010-04-05
vulnerable: 4.1.1 ... 5.3.0 (6 versions)
Cross-site request forgery (CSRF) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote attackers to hijack the authentication of unspecified victims for requests that create queues via the JMSDestination …
- CVE-2017-15709LOWCVSS 3.7EG 3.7✓ Fixed in 5.14.62018-02-13
vulnerable: 5.14.0 ... 5.14.5 (6 versions)
When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was found that certain system details (such as the OS and kernel version) are exposed as plain text.
- CVE-2020-11998CRITICALCVSS 9.8EG 9.8✓ Fixed in 5.15.132020-09-10
vulnerable: 5.15.12
A regression has been introduced in the commit preventing JMX re-bind. By passing an empty environment map to RMIConnectorServer, instead of the map that contains the authentication credentials, it leaves ActiveMQ open to the following att…
- CVE-2020-13920MEDIUMCVSS 5.9EG 5.9✓ Fixed in 5.15.122020-09-10
vulnerable: 4.1.1 ... 5.9.1 (55 versions)
Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the "jmxrmi" entry. It is possible to connect to the registry without authentication and call the rebind method to rebind jmxrmi to…
- CVE-2020-13947MEDIUMCVSS 6.1EG 6.1✓ Fixed in 5.15.142021-02-08
vulnerable: 4.1.1 ... 5.9.1 (57 versions)
An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the message.jsp page of Apache ActiveMQ versions 5.15.12 through 5.16.0.
- CVE-2021-26117HIGHCVSS 7.5EG 7.5✓ Fixed in 5.15.142021-01-27
vulnerable: 4.1.1 ... 5.9.1 (57 versions)
The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous…
Check whether org.apache.activemq:activemq-parent is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.apache.activemq:activemq-parent CVEs against the assets you own.
Start Free Scan →