Common Vulnerabilities and Exposures assigned an identifier CVE-2010-0684 to the following vulnerability: Cross-site scripting (XSS) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote authenticated users to inject arbitrary web script or HTML via the JMSDestination parameter in a queue action. References: [1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0684 [2] http://www.securityfocus.com/archive/1/archive/1/510419/100/0/threaded [3] http://www.rajatswarup.com/CVE-2010-0684.txt [4] http://activemq.apache.org/activemq-531-release.html [5] https://issues.apache.org/activemq/browse/AMQ-2613 [6] https://issues.apache.org/activemq/browse/AMQ-2625 [7] http://www.securityfocus.com/bid/39119 [8] http://securitytracker.com/id?1023778 [9] http://secunia.com/advisories/39223 [10] http://xforce.iss.net/xforce/xfdb/57397
I don't mind but how come I became CCed on this? Steve.
Statement: Not vulnerable. Apache ActiveMQ is not shipped with any supported Red Hat products.