Bug 1848045 (CVE-2020-1941) - CVE-2020-1941 activemq: Cross-site scripting in webconsole admin GUI
Summary: CVE-2020-1941 activemq: Cross-site scripting in webconsole admin GUI
Keywords:
Status: CLOSED WONTFIX
Alias: CVE-2020-1941
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 1848046
TreeView+ depends on / blocked
 
Reported: 2020-06-17 14:51 UTC by Pedro Sampaio
Modified: 2023-10-06 20:40 UTC (History)
74 users (show)

Fixed In Version: activemq-5.15.12, activemq-5.15.13
Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in activemq. The webconsole admin GUI is open to XSS, in the view that lists the contents of a queue.
Clone Of:
Environment:
Last Closed: 2020-08-13 15:15:18 UTC
Embargoed:


Attachments (Terms of Use)

Description Pedro Sampaio 2020-06-17 14:51:24 UTC
In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in the view that lists the contents of a queue.

References:

http://activemq.apache.org/security-advisories.data/CVE-2020-1941-announcement.txt

Comment 6 Jonathan Christison 2020-06-18 16:51:32 UTC
This vulnerability is out of security support scope for the following products:
* Red Hat JBoss Fuse 6
* Red Hat JBoss A-MQ 6
* Red Hat JBoss Fuse Service Works 6
* Red Hat JBoss Data Grid 7

Please refer to https://access.redhat.com/support/policy/updates/jboss_notes for more details

Comment 11 Joshua Padman 2020-06-23 05:24:32 UTC
RHV consumes from EAP7 channels which are not affected, hence RHV is also not affected.

Comment 12 Product Security DevOps Team 2020-08-13 15:15:18 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2020-1941


Note You need to log in before you can comment on or make changes to this bug.