Loading HuntDB...

GHSA-hvwm-2624-rp9x

GitHub Security Advisory

Apache ActiveMQ web console vulnerable to Cross-site Scripting

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the queue.jsp page of Apache ActiveMQ versions 5.0.0 to 5.15.5. The root cause of this issue is improper data filtering of the QueueFilter parameter.

Affected Packages

Maven org.apache.activemq:activemq-web-console
Affected versions: 5.0.0 (fixed in 5.15.6)

Related CVEs

Key Information

GHSA ID
GHSA-hvwm-2624-rp9x
Published
October 30, 2018 8:48 PM
Last Modified
March 14, 2024 10:11 PM
CVSS Score
5.0 /10
Primary Ecosystem
Maven
Primary Package
org.apache.activemq:activemq-web-console
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 27, 2025 6:35 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.