CVE-2010-1244
published 2010-04-05CVE-2010-1244: Cross-site request forgery (CSRF) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote attackers to hijack the…
PriorityP424medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.08%
61.6th percentile
Cross-site request forgery (CSRF) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote attackers to hijack the authentication of unspecified victims for requests that create queues via the JMSDestination parameter in a queue action.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | activemq | <= 5.3.0 | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
ActiveMQ: CSRF in createDestination
vendor_redhat·2010-02-24·CVSS 6.8
CVE-2010-1244 [MEDIUM] CWE-352 ActiveMQ: CSRF in createDestination
ActiveMQ: CSRF in createDestination
Cross-site request forgery (CSRF) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote attackers to hijack the authentication of unspecified victims for requests that create queues via the JMSDestination parameter in a queue action.
Statement: Not vulnerable. Apache ActiveMQ is not shipped with any supported Red Hat products.
VulDB
Apache ActiveMQ up to 5.3.0 JMSDestination cross-site request forgery (XFDB-57398 / SA39223)
vuldb·2026-05-05·CVSS 6.8
CVE-2010-1244 [MEDIUM] Apache ActiveMQ up to 5.3.0 JMSDestination cross-site request forgery (XFDB-57398 / SA39223)
A vulnerability, which was classified as problematic, was found in Apache ActiveMQ. The affected element is an unknown function. Such manipulation of the argument JMSDestination leads to cross-site request forgery.
This vulnerability is documented as CVE-2010-1244. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.
GHSA
Cross-site request forgery in Apache ActiveMQ
ghsa·2022-05-02
CVE-2010-1244 [MEDIUM] CWE-352 Cross-site request forgery in Apache ActiveMQ
Cross-site request forgery in Apache ActiveMQ
Cross-site request forgery (CSRF) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote attackers to hijack the authentication of unspecified victims for requests that create queues via the JMSDestination parameter in a queue action.
OSV
Cross-site request forgery in Apache ActiveMQ
osv·2022-05-02
CVE-2010-1244 [MEDIUM] Cross-site request forgery in Apache ActiveMQ
Cross-site request forgery in Apache ActiveMQ
Cross-site request forgery (CSRF) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote attackers to hijack the authentication of unspecified victims for requests that create queues via the JMSDestination parameter in a queue action.
No detection rules found.
No public exploits indexed.
http://activemq.apache.org/activemq-531-release.htmlhttp://secunia.com/advisories/39223https://exchange.xforce.ibmcloud.com/vulnerabilities/57398https://issues.apache.org/activemq/browse/AMQ-2613https://issues.apache.org/activemq/browse/AMQ-2625http://activemq.apache.org/activemq-531-release.htmlhttp://secunia.com/advisories/39223https://exchange.xforce.ibmcloud.com/vulnerabilities/57398https://issues.apache.org/activemq/browse/AMQ-2613https://issues.apache.org/activemq/browse/AMQ-2625
2010-04-05
Published