CVE-2020-13947

Severity
6.1MEDIUM
EPSS
4.0%
top 11.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 8
Latest updateJan 17

Description

An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the message.jsp page of Apache ActiveMQ versions 5.15.12 through 5.16.0.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages6 packages

NVDapache/activemq5.16.05.16.1+1
Mavenorg.apache.activemq:activemq-parent5.16.05.16.1+1
CVEListV5apache_activemqApache ActiveMQ version prior to 5.15.13 and 5.16.1
Debianactivemq< 5.16.1-1+2

Patches

🔴Vulnerability Details

4
GHSA
Cross-site scripting (XSS) in Apache ActiveMQ2022-02-09
OSV
Cross-site scripting (XSS) in Apache ActiveMQ2022-02-09
CVEList
CVE-2020-13947: An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the message2021-02-08
OSV
CVE-2020-13947: An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the message2021-02-08

🔍Detection Rules

2
Suricata
ET WEB_SPECIFIC_APPS Apache ActiveMQ Web Console message jsp Cross-Site Scripting (CVE-2020-13947) M12025-01-17
Suricata
ET WEB_SPECIFIC_APPS Apache ActiveMQ Web Console message jsp Cross-Site Scripting (CVE-2020-13947) M22025-01-17

📋Vendor Advisories

1
Debian
CVE-2020-13947: activemq - An instance of a cross-site scripting vulnerability was identified to be present...2020
CVE-2020-13947 (MEDIUM CVSS 6.1) | An instance of a cross-site scripti | cvebase.io