Description
Multiple cross-site scripting (XSS) vulnerabilities in the web based administration console in Apache ActiveMQ 5.x before 5.10.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Remediation
References
http://activemq.apache.org/security-advisories.data/CVE-2014-8110-announcement.txt
http://www.securityfocus.com/bid/72511
http://seclists.org/oss-sec/2015/q1/427
http://secunia.com/advisories/62649
https://exchange.xforce.ibmcloud.com/vulnerabilities/100724
https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2%40%3Ccommits.activemq.apache.org%3E
Related Vulnerabilities
CVE-2022-22984 Vulnerability in npm package @snyk/snyk-hex-plugin
CVE-2023-49068 Vulnerability in maven package org.apache.dolphinscheduler:dolphinscheduler-api
CVE-2013-2055 Vulnerability in maven package org.apache.wicket:wicket-core
CVE-2023-36542 Vulnerability in maven package org.apache.nifi:nifi-jms-processors
CVE-2021-20195 Vulnerability in maven package org.keycloak:keycloak-core