CVE-2020-13932: XSS
A flaw was found in activemq. A specifically crafted MQTT packet which has an XSS payload as client-id or topic name can exploit this vulnerability. The XSS payload is being injected into the admin console's browser. The XSS payload is triggered in the diagram plugin; queue node and the info section.
Other sources
A specifically crafted MQTT packet which has an XSS payload as client-id or topic name can exploit this vulnerability. The XSS payload is being injected into the admin console's browser. The XSS payload is triggered in the diagram plugin; queue node and the info section.
Reference: https://activemq.apache.org/security-advisories.data/CVE-2020-13932-announcement.txt
— Red Hat
In Apache ActiveMQ Artemis 2.5.0 to 2.13.0, a specially crafted MQTT packet which has an XSS payload as client-id or topic name can exploit this vulnerability. The XSS payload is being injected into the admin console's browser. The XSS payload is triggered in the diagram plugin; queue node and the info section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/Apache ActiveMQ Artemisto a version that resolves this vulnerability.Fixed in 2.14.0
Event History
Frequently Asked Questions
What is CVE-2020-13932?
CVE-2020-13932 is a vulnerability found in Apache ActiveMQ Artemis. A specially crafted MQTT packet with an XSS payload can exploit this vulnerability.
What is the severity of CVE-2020-13932?
The severity of CVE-2020-13932 is medium, with a CVSS severity score of 6.5.
How can CVE-2020-13932 be exploited?
CVE-2020-13932 can be exploited by sending a specially crafted MQTT packet with an XSS payload as the client-id or topic name.
How can I fix CVE-2020-13932?
To fix CVE-2020-13932, update Apache ActiveMQ Artemis to version 2.14.0.
What is the Common Vulnerabilities and Exposures (CVE) identifier for this vulnerability?
The Common Vulnerabilities and Exposures (CVE) identifier for this vulnerability is CVE-2020-13932.