oss-sec mailing list archives

[ANNOUNCE] CVE-2016-0734: ActiveMQ Web Console - Clickjacking


From: Christopher Shannon <christopher.l.shannon () gmail com>
Date: Thu, 10 Mar 2016 07:46:01 -0500

There following security vulnerability was reported against Apache
ActiveMQ 5.13.1 and older versions.

Please check the following document and see if you’re affected by the issue.

http://activemq.apache.org/security-advisories.data/CVE-2016-0734-announcement.txt

Apache ActiveMQ 5.13.2 and newer with appropriate fixes was released and
available for upgrade.

Current thread: