HTTP管理认证中的会话固定漏洞允许远程攻击者通过重用成功登录后保留的会话标识符,获得对已认证管理会话的未授权访问。 此问题影响 Apache Qpid Broker-J:版本 10.1.0 及之前版本。 建议用户升级至版本 10.1.1,该版本已修复此问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Qpid Broker-J | 0 ~ 10.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92550 | Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authen | |
| CVE-2026-92560 | Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authen | |
| CVE-2026-92573 | Apache Qpid Broker-J: Uncontrolled resource consumption during AMQP delivery decompression | |
| CVE-2026-92564 | Apache Qpid Broker-J: Unbounded type nesting can lead to stack overflow pre-authentication | |
| CVE-2026-92608 | Apache Qpid Broker-J: Incomplete property conversion handling from AMQP 1.0 to AMQP 0-10 |
No comments yet