Red Hat Bugzilla – Bug 924446
CVE-2013-1879 ActiveMQ: XSS vulnerability in scheduled.jsp
Last modified: 2016-03-04 07:38:02 EST
Dejan Bosanac reports: If a string such as: * * * * *<script>alert(1)</script> is entered into cron of a message, JS code will be executed on the scheduled.jsp page. External references: https://issues.apache.org/jira/browse/AMQ-4397
Created activemq tracking bugs for this issue Affects: fedora-18 [bug 924448]
This issue has been addressed in following products: Fuse MQ Enterprise 7.1.0 Via RHSA-2013:1029 https://rhn.redhat.com/errata/RHSA-2013-1029.html