CVE-2010-0684: XSS
Published Apr 5, 2010
·Updated
Cross-site scripting (XSS) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote authenticated users to inject arbitrary web script or HTML via the JMSDestination parameter in a queue action.
Affected Software
24 affected componentsFixes available
maven/org.apache.activemq:activemq-parent<5.3.1
5.3.1
Apache ActiveMQ<=5.3.0
Apache ActiveMQ=1.1
Apache ActiveMQ=1.2
Apache ActiveMQ=1.3
Apache ActiveMQ=1.4
Apache ActiveMQ=1.5
Apache ActiveMQ=2.0
Apache ActiveMQ=2.1
Apache ActiveMQ=3.0
Apache ActiveMQ=3.1
Apache ActiveMQ=3.2
Apache ActiveMQ=3.2.1
Apache ActiveMQ=3.2.2
Apache ActiveMQ=4.0
Apache ActiveMQ=4.0-m4
Apache ActiveMQ=4.0-rc2
Apache ActiveMQ=4.0.1
Apache ActiveMQ=4.0.2
Apache ActiveMQ=4.1.0
Apache ActiveMQ=4.1.1
Apache ActiveMQ=5.0.0
Apache ActiveMQ=5.1.0
Apache ActiveMQ=5.2.0
Remediation
Patch Available
Patch Available
Event History
Apr 5, 2010
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:30 PM
RemedyDescriptionSeverityWeaknessAffected Software
May 2, 2022
Advisory Published
via GitHub·06:14 AM
Frequently Asked Questions
1
What is the severity of CVE-2010-0684?
CVE-2010-0684 is classified as a medium severity cross-site scripting vulnerability.
2
How do I fix CVE-2010-0684?
To fix CVE-2010-0684, upgrade Apache ActiveMQ to version 5.3.1 or later.
3
Who is affected by CVE-2010-0684?
CVE-2010-0684 affects Apache ActiveMQ versions prior to 5.3.1 and specific earlier versions.
4
What kind of attack can be executed using CVE-2010-0684?
An attacker can exploit CVE-2010-0684 to inject arbitrary web script or HTML into the application.
5
Is CVE-2010-0684 a remote exploit?
Yes, CVE-2010-0684 can be exploited remotely by authenticated users.