Red Hat Bugzilla – Bug 1622774
CVE-2018-8006 activemq: Cross-site scripting (XSS) via QueueFilter parameter
Last modified: 2018-10-19 17:53:23 EDT
Apache ActiveMQ before version 5.15.5 is vulnerable to cross-site scripting (XSS) flaw via the QueueFilter parameter. An attacker could exploit this by feeding a URL encoded script to the QueueFilter parameter in the URI. External Reference: https://www.trustwave.com/Resources/Security-Advisories/Advisories/TWSL2018-008/?fid=11632 Upstream Bug: https://issues.apache.org/jira/browse/AMQ-6954 Upstream Patches: https://git-wip-us.apache.org/repos/asf?p=activemq.git;h=d25de5d https://git-wip-us.apache.org/repos/asf?p=activemq.git;h=d8c80a9
Created activemq tracking bugs for this issue: Affects: fedora-all [bug 1622775]