oss-sec mailing list archives

[ANNOUNCE] CVE-2016-6810: ActiveMQ Web Console - Cross-Site Scripting


From: Christopher Shannon <christopher.l.shannon () gmail com>
Date: Fri, 9 Dec 2016 10:01:08 -0500

The following security vulnerability was reported against Apache
ActiveMQ 5.14.1 and older versions.

Please check the following document and see if you’re affected by the issue.

http://activemq.apache.org/security-advisories.data/CVE-2016-6810-announcement.txt

Apache ActiveMQ 5.14.2 has been released with appropriate fixes and is
available for upgrade.

Current thread: