Bugtraq mailing list archives

[ANNOUNCE] CVE-2016-0782: ActiveMQ Web Console - Cross-Site Scripting


From: Christopher Shannon <christopher.l.shannon () gmail com>
Date: Thu, 10 Mar 2016 07:53:54 -0500

There following security vulnerability was reported against Apache
ActiveMQ 5.13.0 and older versions.

Please check the following document and see if you’re affected by the issue.

http://activemq.apache.org/security-advisories.data/CVE-2016-0782-announcement.txt

Apache ActiveMQ 5.13.1 and newer with appropriate fixes was released and
available for upgrade.


Current thread: