CVE-2018-11775

Severity
7.4HIGH
EPSS
0.5%
top 34.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 10
Latest updateJul 23

Description

TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vulnerable to a MITM attack between a Java application using the ActiveMQ client and the ActiveMQ server. This is now enabled by default.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 2.2 | Impact: 5.2

Affected Packages6 packages

NVDapache/activemq< 5.15.6
Debianactivemq< 5.15.6-1+2

Patches

🔴Vulnerability Details

5
OSV
activemq vulnerabilities2024-07-23
OSV
Improper Certificate Validation in Apache activemq-client2018-10-19
GHSA
Improper Certificate Validation in Apache activemq-client2018-10-19
OSV
CVE-2018-11775: TLS hostname verification when using the Apache ActiveMQ Client before 52018-09-10
CVEList
CVE-2018-11775: TLS hostname verification when using the Apache ActiveMQ Client before 52018-09-10

📋Vendor Advisories

3
Ubuntu
Apache ActiveMQ vulnerabilities2024-07-23
Red Hat
activemq: ActiveMQ Client Missing TLS Hostname Verification2018-09-10
Debian
CVE-2018-11775: activemq - TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 wa...2018

💬Community

2
Bugzilla
CVE-2018-11775 activemq: ActiveMQ Client Missing TLS Hostname Verification [fedora-all]2018-09-14
Bugzilla
CVE-2018-11775 activemq: ActiveMQ Client Missing TLS Hostname Verification2018-09-14