CVE-2020-1941
published 2020-05-14CVE-2020-1941: In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in the view that lists the contents of a queue.
PriorityP430medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
6.21%
92.7th percentile
In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in the view that lists the contents of a queue.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | activemq | >= 0 < 5.16.0-1 | 5.16.0-1 |
| apache | activemq | >= 0 < 5.16.0-1 | 5.16.0-1 |
| apache | activemq | >= 0 < 5.16.0-1 | 5.16.0-1 |
| apache | activemq | 5.0.0 – 5.15.11 | — |
| debian | activemq | < activemq 5.16.0-1 (bookworm) | activemq 5.16.0-1 (bookworm) |
| oracle | communications_diameter_signaling_router | 8.0.0 – 8.2.2 | — |
| oracle | communications_element_manager | — | — |
| oracle | communications_element_manager | — | — |
| oracle | communications_element_manager | — | — |
| oracle | communications_session_report_manager | — | — |
| oracle | communications_session_report_manager | — | — |
| oracle | communications_session_report_manager | — | — |
| oracle | communications_session_route_manager | — | — |
| oracle | communications_session_route_manager | — | — |
| oracle | communications_session_route_manager | — | — |
| oracle | enterprise_repository | — | — |
| oracle | flexcube_private_banking | — | — |
| oracle | flexcube_private_banking | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_debian6.1LOW
vendor_oracle6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Communications Risk Matrix: IDIH (Apache ActiveMQ) — CVE-2020-1941
vendor_oracle·2020-10-15·CVSS 6.1
CVE-2020-1941 [MEDIUM] Oracle Oracle Communications Risk Matrix: IDIH (Apache ActiveMQ) — CVE-2020-1941
Oracle Oracle Communications Risk Matrix: IDIH (Apache ActiveMQ) vulnerability
CVE: CVE-2020-1941
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2020 (OCT 2020)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Workorders (Apache ActiveMQ) — CVE-2020-1941
vendor_oracle·2020-07-15·CVSS 6.1
CVE-2020-1941 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Workorders (Apache ActiveMQ) — CVE-2020-1941
Oracle Oracle Communications Applications Risk Matrix: Workorders (Apache ActiveMQ) vulnerability
CVE: CVE-2020-1941
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2020 (JUL 2020)
Red Hat
activemq: Cross-site scripting in webconsole admin GUI
vendor_redhat·2020-05-14·CVSS 6.1
CVE-2020-1941 [MEDIUM] CWE-79 activemq: Cross-site scripting in webconsole admin GUI
activemq: Cross-site scripting in webconsole admin GUI
In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in the view that lists the contents of a queue.
A flaw was found in activemq. The webconsole admin GUI is open to XSS, in the view that lists the contents of a queue.
Package: activemq (JBoss Developer Studio 11) - Out of support scope
Package: mqtt-client (Red Hat AMQ Broker 7) - Not affected
Package: activemq-artemis (Red Hat Decision Manager 7) - Not affected
Package: activemq (Red Hat Fuse 7) - Not affected
Package: activemq (Red Hat JBoss A-MQ 6) - Out of support scope
Package: activemq-artemis (Red Hat JBoss Data Grid 7) - Out of support scope
Package: activemq-artemis (Red Hat JBoss Enterprise Application Platform 7) - Not affected
Package: a
Debian
CVE-2020-1941: activemq - In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in...
vendor_debian·2020·CVSS 6.1
CVE-2020-1941 [MEDIUM] CVE-2020-1941: activemq - In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in...
In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in the view that lists the contents of a queue.
Scope: local
bookworm: resolved (fixed in 5.16.0-1)
bullseye: resolved (fixed in 5.16.0-1)
sid: resolved (fixed in 5.16.0-1)
trixie: resolved (fixed in 5.16.0-1)
GHSA
Apache ActiveMQ webconsole admin GUI is open to XSS
ghsa·2020-05-21
CVE-2020-1941 [MEDIUM] CWE-79 Apache ActiveMQ webconsole admin GUI is open to XSS
Apache ActiveMQ webconsole admin GUI is open to XSS
In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in the view that lists the contents of a queue.
OSV
Apache ActiveMQ webconsole admin GUI is open to XSS
osv·2020-05-21
CVE-2020-1941 [MEDIUM] Apache ActiveMQ webconsole admin GUI is open to XSS
Apache ActiveMQ webconsole admin GUI is open to XSS
In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in the view that lists the contents of a queue.
OSV
CVE-2020-1941: In Apache ActiveMQ 5
osv·2020-05-14·CVSS 6.1
CVE-2020-1941 [MEDIUM] CVE-2020-1941: In Apache ActiveMQ 5
In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in the view that lists the contents of a queue.
No detection rules found.
No public exploits indexed.
http://activemq.apache.org/security-advisories.data/CVE-2020-1941-announcement.txthttps://lists.apache.org/thread.html/r946488fb942fd35c6a6e0359f52504a558ed438574a8f14d36d7dcd7%40%3Ccommits.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/rb2fd3bf2dce042e0ab3f3c94c4767c96bb2e7e6737624d63162df36d%40%3Ccommits.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/re4672802b0e5ed67c08c9e77057d52138e062f77cc09581b723cf95a%40%3Ccommits.activemq.apache.org%3Ehttps://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttp://activemq.apache.org/security-advisories.data/CVE-2020-1941-announcement.txthttps://lists.apache.org/thread.html/r946488fb942fd35c6a6e0359f52504a558ed438574a8f14d36d7dcd7%40%3Ccommits.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/rb2fd3bf2dce042e0ab3f3c94c4767c96bb2e7e6737624d63162df36d%40%3Ccommits.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/re4672802b0e5ed67c08c9e77057d52138e062f77cc09581b723cf95a%40%3Ccommits.activemq.apache.org%3Ehttps://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.html
2020-05-14
Published