CVE-2022-35278
published 2022-08-23CVE-2022-35278: In Apache ActiveMQ Artemis prior to 2.24.0, an attacker could show malicious content and/or redirect users to a malicious URL in the web console by using HTML…
PriorityP427medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
1.41%
69.7th percentile
In Apache ActiveMQ Artemis prior to 2.24.0, an attacker could show malicious content and/or redirect users to a malicious URL in the web console by using HTML in the name of an address or queue.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | artemis | < 2.24.0 | 2.24.0 |
| apache_software_foundation | apache_activemq_artemis | unspecified – 2.23.1 | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
osv6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
activemq-artemis: AMQ Broker web console HTML Injection
vendor_redhat·2022-08-18·CVSS 6.1
CVE-2022-35278 [MEDIUM] CWE-74 activemq-artemis: AMQ Broker web console HTML Injection
activemq-artemis: AMQ Broker web console HTML Injection
In Apache ActiveMQ Artemis prior to 2.24.0, an attacker could show malicious content and/or redirect users to a malicious URL in the web console by using HTML in the name of an address or queue.
A security vulnerability was found in ActiveMQ Artemis. This flaw allows an attacker to show malicious content and redirect users to a malicious URL in the web console by using HTML in the name of an address or queue.
Package: artemis-plugin (Red Hat Fuse 7) - Not affected
GHSA
HTML Injection in ActiveMQ Artemis Web Console
ghsa·2022-08-24
CVE-2022-35278 [MEDIUM] CWE-79 HTML Injection in ActiveMQ Artemis Web Console
HTML Injection in ActiveMQ Artemis Web Console
In Apache ActiveMQ Artemis prior to 2.24.0, an attacker could show malicious content and/or redirect users to a malicious URL in the web console by using HTML in the name of an address or queue.
OSV
HTML Injection in ActiveMQ Artemis Web Console
osv·2022-08-24
CVE-2022-35278 [MEDIUM] HTML Injection in ActiveMQ Artemis Web Console
HTML Injection in ActiveMQ Artemis Web Console
In Apache ActiveMQ Artemis prior to 2.24.0, an attacker could show malicious content and/or redirect users to a malicious URL in the web console by using HTML in the name of an address or queue.
OSV
CVE-2022-35278: In Apache ActiveMQ Artemis prior to 2
osv·2022-08-23·CVSS 6.1
CVE-2022-35278 [MEDIUM] CVE-2022-35278: In Apache ActiveMQ Artemis prior to 2
In Apache ActiveMQ Artemis prior to 2.24.0, an attacker could show malicious content and/or redirect users to a malicious URL in the web console by using HTML in the name of an address or queue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-08-23
Published