CVE-2022-35278: HTML Injection in ActiveMQ Artemis Web Console

Published Jul 22, 2022
·
Updated

A security vulnerability was found in ActiveMQ Artemis. This flaw allows an attacker to show malicious content and redirect users to a malicious URL in the web console by using HTML in the name of an address or queue.

Other sources

HTML injection is a type of injection vulnerability that occurs when a user is able to control an input point and is able to inject arbitrary HTML code into a vulnerable web page. This vulnerability can have many consequences, like disclosure of a user’s session cookies that could be used to impersonate the victim, or, more generally, it can allow the attacker to modify the page content seen by the victims. This vulnerability occurs when user input is not correctly sanitized and the output is not encoded. An injection allows the attacker to send a malicious HTML page to a victim. The targeted browser will not be able to distinguish (trust) legitimate parts from malicious parts of the page, and consequently will parse and execute the whole page in the victim’s context.

Red Hat

In Apache ActiveMQ Artemis prior to 2.24.0, an attacker could show malicious content and/or redirect users to a malicious URL in the web console by using HTML in the name of an address or queue.

Affected Software

4 affected components
Apache ActiveMQ Artemis<2.24.0
NetApp Active Iq Unified Manager Windows
NetApp OnCommand Workflow Automation
Apache ARTEMIS<2.24.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Apache ActiveMQ Artemis to a version that resolves this vulnerability.

    Fixed in 2.24.0

Event History

Jul 22, 2022
Data Sourced
via Red Hat·07:54 AM
DescriptionSeverityAffected Software
Aug 18, 2022
CVE Published
12:00 AM
Data Sourced
12:00 AM
RemedyDescriptionSeverityWeaknessAffected Software
Aug 23, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

What is CVE-2022-35278?

CVE-2022-35278 is a security vulnerability found in ActiveMQ Artemis that allows an attacker to show malicious content and redirect users to a malicious URL in the web console.

2

How can an attacker exploit CVE-2022-35278?

An attacker can exploit CVE-2022-35278 by using HTML in the name of an address or queue to display malicious content and redirect users to a malicious URL in the web console.

3

Which versions of Apache ActiveMQ Artemis are affected by CVE-2022-35278?

Versions of Apache ActiveMQ Artemis prior to 2.24.0 are affected by CVE-2022-35278.

4

What is the severity of CVE-2022-35278?

CVE-2022-35278 has a severity rating of high (6.1).

5

How can I fix CVE-2022-35278?

To fix CVE-2022-35278, upgrade to Apache ActiveMQ Artemis version 2.24.0 or later.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203