CVE-2010-1587
published 2010-04-28CVE-2010-1587: The Jetty ResourceHandler in Apache ActiveMQ 5.x before 5.3.2 and 5.4.x before 5.4.0 allows remote attackers to read JSP source code via a // (slash slash)…
PriorityP351medium5CVSS 2.0
AVNACLAuNCPINAN
EXPLOIT
EPSS
78.02%
99.5th percentile
The Jetty ResourceHandler in Apache ActiveMQ 5.x before 5.3.2 and 5.4.x before 5.4.0 allows remote attackers to read JSP source code via a // (slash slash) initial substring in a URI for (1) admin/index.jsp, (2) admin/queues.jsp, or (3) admin/topics.jsp.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
| apache | activemq | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect HTTP requests to the ActiveMQ web console (default port 8161) where the URI path begins with a double-slash (//) — this is the specific trigger for the Jetty ResourceHandler source disclosure. ↗
- →Focus detection on the three known vulnerable JSP paths accessed via double-slash prefix: //admin/index.jsp, //admin/queues.jsp, and //admin/topics.jsp on port 8161. ↗
- →This vulnerability is also associated with a directory traversal variant on Windows systems (ActiveMQ 5.3.1 and 5.3.2); monitor for path traversal patterns in addition to double-slash URIs on the same port. ↗
- →This vulnerability may be related to BID 27117 (Jetty Double Slash URI Information Disclosure); consider correlating with Jetty-level detections for the same double-slash URI pattern. ↗
- ·Affected versions are Apache ActiveMQ 5.x before 5.3.2 and 5.4.x before 5.4.0 only; patched versions are not vulnerable. ↗
- ·Red Hat confirmed it does not ship Apache ActiveMQ in any supported product, so Red Hat-based environments are not affected by this CVE. ↗
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat5.0MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache ActiveMQ Sensitive Information Disclosure via the Jetty ResourceHandler
ghsa·2022-05-14
CVE-2010-1587 [MEDIUM] CWE-20 Apache ActiveMQ Sensitive Information Disclosure via the Jetty ResourceHandler
Apache ActiveMQ Sensitive Information Disclosure via the Jetty ResourceHandler
The Jetty ResourceHandler in Apache ActiveMQ 5.x before 5.3.2 and 5.4.x before 5.4.0 allows remote attackers to read JSP source code via a // (slash slash) initial substring in a URI for (1) admin/index.jsp, (2) admin/queues.jsp, or (3) admin/topics.jsp.
OSV
Apache ActiveMQ Sensitive Information Disclosure via the Jetty ResourceHandler
osv·2022-05-14
CVE-2010-1587 [MEDIUM] Apache ActiveMQ Sensitive Information Disclosure via the Jetty ResourceHandler
Apache ActiveMQ Sensitive Information Disclosure via the Jetty ResourceHandler
The Jetty ResourceHandler in Apache ActiveMQ 5.x before 5.3.2 and 5.4.x before 5.4.0 allows remote attackers to read JSP source code via a // (slash slash) initial substring in a URI for (1) admin/index.jsp, (2) admin/queues.jsp, or (3) admin/topics.jsp.
Red Hat
ActiveMQ JSP source disclosure
vendor_redhat·2010-04-20·CVSS 5.0
CVE-2010-1587 [MEDIUM] ActiveMQ JSP source disclosure
ActiveMQ JSP source disclosure
The Jetty ResourceHandler in Apache ActiveMQ 5.x before 5.3.2 and 5.4.x before 5.4.0 allows remote attackers to read JSP source code via a // (slash slash) initial substring in a URI for (1) admin/index.jsp, (2) admin/queues.jsp, or (3) admin/topics.jsp.
Statement: Not vulnerable. Apache ActiveMQ is not shipped with any supported Red Hat products.
No detection rules found.
Exploit-DB
Apache ActiveMQ 5.2/5.3 - Source Code Information Disclosure
exploitdb·2010-04-22
CVE-2010-1587 Apache ActiveMQ 5.2/5.3 - Source Code Information Disclosure
Apache ActiveMQ 5.2/5.3 - Source Code Information Disclosure
---
source: https://www.securityfocus.com/bid/39636/info
Apache ActiveMQ is prone to a vulnerability that lets attackers access source code because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable computer in the context of the webserver process. Information obtained may aid in further attacks.
Apache ActiveMQ 5.3.1 and prior are vulnerable.
NOTE: This vulnerability may be related to BID 27117 (Jetty Double Slash URI Information Disclosure Vulnerability).
http://www.example.com:8161//admin/index.jsp
http://www.example.com:8161//admin/queues.jsp
http://www.example.com:8161//admin/topics.jsp
Metasploit
Apache ActiveMQ Directory Traversal
metasploit
Apache ActiveMQ Directory Traversal
Apache ActiveMQ Directory Traversal
This module exploits a directory traversal vulnerability in Apache ActiveMQ 5.3.1 and 5.3.2 on Windows systems. The vulnerability exists in the Jetty's ResourceHandler installed with the affected versions. This module has been tested successfully on ActiveMQ 5.3.1 and 5.3.2 over Windows 2003 SP2.
Metasploit
Apache ActiveMQ JSP Files Source Disclosure
metasploit
Apache ActiveMQ JSP Files Source Disclosure
Apache ActiveMQ JSP Files Source Disclosure
This module exploits a source code disclosure in Apache ActiveMQ. The vulnerability is due to the Jetty's ResourceHandler handling of specially crafted URI's starting with //. It has been tested successfully on Apache ActiveMQ 5.3.1 over Windows 2003 SP2 and Ubuntu 10.04.
http://archives.neohapsis.com/archives/fulldisclosure/2010-04/0278.htmlhttp://secunia.com/advisories/39567http://www.osvdb.org/64020http://www.securityfocus.com/archive/1/510896/100/0/threadedhttp://www.securityfocus.com/bid/39636http://www.vupen.com/english/advisories/2010/0979https://issues.apache.org/activemq/browse/AMQ-2700http://archives.neohapsis.com/archives/fulldisclosure/2010-04/0278.htmlhttp://secunia.com/advisories/39567http://www.osvdb.org/64020http://www.securityfocus.com/archive/1/510896/100/0/threadedhttp://www.securityfocus.com/bid/39636http://www.vupen.com/english/advisories/2010/0979https://issues.apache.org/activemq/browse/AMQ-2700
2010-04-28
Published