First published: Mon Apr 05 2010(Updated: )
Cross-site scripting (XSS) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote authenticated users to inject arbitrary web script or HTML via the JMSDestination parameter in a queue action.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.apache.activemq:activemq-parent | <5.3.1 | 5.3.1 |
Apache ActiveMQ | <=5.3.0 | |
Apache ActiveMQ | =1.1 | |
Apache ActiveMQ | =1.2 | |
Apache ActiveMQ | =1.3 | |
Apache ActiveMQ | =1.4 | |
Apache ActiveMQ | =1.5 | |
Apache ActiveMQ | =2.0 | |
Apache ActiveMQ | =2.1 | |
Apache ActiveMQ | =3.0 | |
Apache ActiveMQ | =3.1 | |
Apache ActiveMQ | =3.2 | |
Apache ActiveMQ | =3.2.1 | |
Apache ActiveMQ | =3.2.2 | |
Apache ActiveMQ | =4.0 | |
Apache ActiveMQ | =4.0-m4 | |
Apache ActiveMQ | =4.0-rc2 | |
Apache ActiveMQ | =4.0.1 | |
Apache ActiveMQ | =4.0.2 | |
Apache ActiveMQ | =4.1.0 | |
Apache ActiveMQ | =4.1.1 | |
Apache ActiveMQ | =5.0.0 | |
Apache ActiveMQ | =5.1.0 | |
Apache ActiveMQ | =5.2.0 | |
<=5.3.0 | ||
=1.1 | ||
=1.2 | ||
=1.3 | ||
=1.4 | ||
=1.5 | ||
=2.0 | ||
=2.1 | ||
=3.0 | ||
=3.1 | ||
=3.2 | ||
=3.2.1 | ||
=3.2.2 | ||
=4.0 | ||
=4.0-m4 | ||
=4.0-rc2 | ||
=4.0.1 | ||
=4.0.2 | ||
=4.1.0 | ||
=4.1.1 | ||
=5.0.0 | ||
=5.1.0 | ||
=5.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0684 is classified as a medium severity cross-site scripting vulnerability.
To fix CVE-2010-0684, upgrade Apache ActiveMQ to version 5.3.1 or later.
CVE-2010-0684 affects Apache ActiveMQ versions prior to 5.3.1 and specific earlier versions.
An attacker can exploit CVE-2010-0684 to inject arbitrary web script or HTML into the application.
Yes, CVE-2010-0684 can be exploited remotely by authenticated users.