GHSA-hvwm-2624-rp9x
GitHub Security Advisory
Apache ActiveMQ web console vulnerable to Cross-site Scripting
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the queue.jsp page of Apache ActiveMQ versions 5.0.0 to 5.15.5. The root cause of this issue is improper data filtering of the QueueFilter parameter.
Affected Packages
Maven
org.apache.activemq:activemq-web-console
Affected versions:
5.0.0
(fixed in 5.15.6)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 27, 2025 6:35 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.