Apache ActiveMQ是Apache基金会的一款消息队列中间件。 Apache ActiveMQ 5.19.8之前版本和6.0.0至6.2.7之前版本、Apache ActiveMQ Web Console 5.19.8之前版本和6.0.0至6.2.7之前版本存在跨站脚本漏洞,该漏洞源于Web控制台的浏览页面直接渲染消息ID而未进行清理,导致跨站脚本攻击,允许经过身份验证的生产者发送特制JMS消息ID,当管理员浏览队列时,有效载荷在浏览器中执行。以下版本受到影响:Apache ActiveMQ 5
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache ActiveMQ | < 5.19.8 |
affected |
6.0.0< 6.2.7 |
affected | ||
| Apache Software Foundation | Apache ActiveMQ Web Console | < 5.19.8 |
affected |
6.0.0< 6.2.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache ActiveMQ | 0 ~ 5.19.8 | - |
|
| Apache Software Foundation | Apache ActiveMQ Web Console | 0 ~ 5.19.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54475 | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Temporary destination owners | |
| CVE-2026-53917 | Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Client, Apache ActiveMQ Broker: Unbo | |
| CVE-2026-53916 | Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: Unbounded header buffer in ST | |
| CVE-2026-50750 | Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: Pre-authentication OpenWire | |
| CVE-2026-50734 | Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All: Pre-authentication OpenWire | |
| CVE-2026-49877 | Apache ActiveMQ: Authenticated web users retain admin access by default in the Web Console | |
| CVE-2026-49432 | Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: STOMP negative content-length | |
| CVE-2026-49434 | Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: LdapNetworkConnector instant | |
| CVE-2025-53648 | Apache Gravitino: SQL misconfiguration can access or truncate files |
No comments yet