CVE-2020-1941

Severity
6.1MEDIUM
EPSS
8.9%
top 7.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 14
Latest updateOct 15

Description

In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in the view that lists the contents of a queue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages10 packages

NVDapache/activemq5.0.05.15.11
CVEListV5apache_activemqApache ActiveMQ 5.0.0 to 5.15.11
Debianactivemq< 5.16.0-1+2

🔴Vulnerability Details

4
GHSA
Apache ActiveMQ webconsole admin GUI is open to XSS2020-05-21
OSV
Apache ActiveMQ webconsole admin GUI is open to XSS2020-05-21
CVEList
CVE-2020-1941: In Apache ActiveMQ 52020-05-14
OSV
CVE-2020-1941: In Apache ActiveMQ 52020-05-14

📋Vendor Advisories

4
Oracle
Oracle Oracle Communications Risk Matrix: IDIH (Apache ActiveMQ) — CVE-2020-19412020-10-15
Oracle
Oracle Oracle Communications Applications Risk Matrix: Workorders (Apache ActiveMQ) — CVE-2020-19412020-07-15
Red Hat
activemq: Cross-site scripting in webconsole admin GUI2020-05-14
Debian
CVE-2020-1941: activemq - In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in...2020

💬Community

1
Bugzilla
CVE-2020-1941 activemq: Cross-site scripting in webconsole admin GUI2020-06-17