Apache ActiveMQ Multiple Cross-Site Scripting Vulnerabilities (CVE-2014-8110)
Release date:
Updated on:
Affected Systems:
Apache Group ActiveMQ 5.10.0
Unaffected system:
Apache Group ActiveMQ 5.11.0
Apache Group ActiveMQ 5.10.1
Description:
Bugtraq id: 72511
CVE (CAN) ID: CVE-2014-8110
Apache ActiveMQ is a popular message transmission and integration mode provider.
Apache ActiveMQ 5.0.0-5.10.0 does not properly verify user input. There is a cross-site scripting vulnerability in implementation. Remote attackers use specially crafted URLs to trick users into clicking, then, attackers can execute arbitrary scripts in the user's Web browser to steal the identity authentication creden。 of cookies of victims.
<* Source: & #195; Upper & #194; & #187; & #194; & #191; Georgi gesev
Link: http://xforce.iss.net/xforce/xfdb/100724
*>
Suggestion:
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://activemq.apache.org/security-advisories.data/CVE-2014-8110-announcement.txt
ActiveMQ installation in Linux
ACTIVEMQ server in Ubuntu
Spring + JMS + ActiveMQ + Tomcat Implement Message Service
Set ActiveMQ port and WEB port in Linux
This article permanently updates the link address: