GHSA-jvpp-hxjj-5ccc
GitHub Security Advisory
Improper Input Validation and Missing Authentication for Critical Function in Apache ActiveMQ
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker logged into a compromised broker could use this flaw to achieve denial of service on a connected client.
Affected Packages
Maven
org.apache.activemq:activemq-client
Affected versions:
0
(fixed in 5.14.5)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: September 11, 2025 6:35 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.