cbcvebase.
CVE-2018-8006
published 2018-10-10

CVE-2018-8006: An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the queue.jsp page of Apache…

PriorityP181medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
57.23%
99.0th percentile
An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the queue.jsp page of Apache ActiveMQ versions 5.0.0 to 5.15.5. The root cause of this issue is improper data filtering of the QueueFilter parameter.

Affected

6 ranges
VendorProductVersion rangeFixed in
apacheactivemq>= 0 < 5.15.6-15.15.6-1
apacheactivemq>= 0 < 5.15.6-15.15.6-1
apacheactivemq>= 0 < 5.15.6-15.15.6-1
apacheactivemq5.0.0 – 5.15.5
apache_software_foundationapache_activemq
debianactivemq< activemq 5.15.6-1 (bookworm)activemq 5.15.6-1 (bookworm)

Detection & IOCsextracted from sources · hover to see the quote

path/admin/queues.action?QueueFilter=
pathqueue.jsp
  • Monitor HTTP requests to the ActiveMQ admin console queue.jsp page for unsanitized/URL-encoded script content in the QueueFilter parameter
  • Nuclei/probe detection checks for XSS payload alert("1") reflected in response body with Content-Type /html and HTTP 200 status on the ActiveMQ admin queue endpoint
  • Vulnerable parameter is QueueFilter on the queue.jsp page of the ActiveMQ web-based administration console; filter or alert on this parameter containing script tags or encoded JavaScript
  • ·Vulnerability affects Apache ActiveMQ versions 5.0.0 through 5.15.5 only; versions 5.15.6 and later are patched
  • ·activemq-artemis (used in Red Hat JBoss EAP 7, Decision Manager 7, Process Automation 7, Single Sign-On 7, JBoss Data Grid 7, Red Hat Virtualization 4) is NOT affected — only the classic activemq package is vulnerable
  • ·Red Hat Single Sign-On does not include the vulnerable web console components and is not affected

CVSS provenance

nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vulncheck6.1MEDIUM
vendor_debian6.1LOW
vendor_redhat6.1MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.