Apache ActiveMQ
cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*
- < 5.19.7
- >= 6.0.0, < 6.2.6
A cross-site scripting vulnerability has been identified in Apache ActiveMQ and Apache ActiveMQ Web. The issue arises in the MessageServlet of the ActiveMQ web console API, which improperly neutralizes input during web page generation. Specifically, the servlet copies all JMS message properties into HTTP response headers without validation. This flaw can be exploited to overwrite and inject security headers by manipulating JMS messages returned by the servlet. The vulnerability affects Apache ActiveMQ versions prior to 5.19.7 and 6.0.0 versions prior to 6.2.6, as well as Apache ActiveMQ Web versions prior to 5.19.7 and 6.0.0 versions prior to 6.2.6.
Exploitation of this vulnerability allows for cross-site scripting attacks by injecting malicious scripts into HTTP response headers, which could be executed by the user's browser.
Users are advised to upgrade to Apache ActiveMQ version 5.19.7 or 6.2.6, both of which address this vulnerability. The MessageServlet has also been deprecated and disabled by default.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.