First published: Tue Feb 13 2018(Updated: )
When using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 it was found that certain system details (such as the OS and kernel version) are exposed as plain text.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache ActiveMQ | >=5.14.0<=5.15.2 | |
maven/org.apache.activemq:activemq-parent | >=5.14.0<5.14.6 | 5.14.6 |
maven/org.apache.activemq:activemq-parent | >=5.15.0<5.15.3 | 5.15.3 |
maven/org.apache.activemq:activemq-openwire-generator | >=5.14.0<5.15.3 | 5.15.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2017-15709.
The severity level of CVE-2017-15709 is medium with a severity value of 3.7.
ActiveMQ versions 5.14.0 to 5.15.2 are affected by CVE-2017-15709.
In ActiveMQ versions 5.14.0 to 5.15.2, certain system details such as the OS and kernel version are exposed as plain text.
Yes, there are references for CVE-2017-15709. You can find them at the following links: [Reference 1](https://lists.apache.org/thread.html/03f91b1fb85686a848cee6b90112cf6059bd1b21b23bacaa11a962e1@%3Cdev.activemq.apache.org%3E), [Reference 2](https://lists.apache.org/thread.html/2b5c0039197a4949f29e1e2c9441ab38d242946b966f61c110808bcc@%3Ccommits.activemq.apache.org%3E), [Reference 3](https://lists.apache.org/thread.html/2b6f04a552c6ec2de6563c2df3bba813f0fe9c7e22cce27b7829db89@%3Cdev.activemq.apache.org%3E).