First published: Fri Jul 22 2022(Updated: )
A security vulnerability was found in ActiveMQ Artemis. This flaw allows an attacker to show malicious content and redirect users to a malicious URL in the web console by using HTML in the name of an address or queue.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache ActiveMQ Artemis | <2.24.0 | |
Netapp Active Iq Unified Manager Windows | ||
NetApp OnCommand Workflow Automation |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-35278 is a security vulnerability found in ActiveMQ Artemis that allows an attacker to show malicious content and redirect users to a malicious URL in the web console.
An attacker can exploit CVE-2022-35278 by using HTML in the name of an address or queue to display malicious content and redirect users to a malicious URL in the web console.
Versions of Apache ActiveMQ Artemis prior to 2.24.0 are affected by CVE-2022-35278.
CVE-2022-35278 has a severity rating of high (6.1).
To fix CVE-2022-35278, upgrade to Apache ActiveMQ Artemis version 2.24.0 or later.