CVE-2010-1244
EPSS 0.44%Cross-site request forgery in Apache ActiveMQ
Published: 5/2/2022Modified: 11/28/2024
Also known as:GHSA-33j4-8vcr-f79v
Description
Cross-site request forgery (CSRF) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote attackers to hijack the authentication of unspecified victims for requests that create queues via the JMSDestination parameter in a queue action.
Affected packages (1)
- Maven/org.apache.activemq:activemq-parentfrom 0, < 5.3.1
References (9)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2010-1244
- WEBhttp://activemq.apache.org/activemq-531-release.html
- WEBhttp://secunia.com/advisories/39223
- WEBhttps://exchange.xforce.ibmcloud.com/vulnerabilities/57398
- WEBhttps://github.com/apache/activemq
- WEBhttps://github.com/apache/activemq/commit/1f464b9412e1b1c08d40c8ffac40edd52731da48
- WEBhttps://github.com/apache/activemq/commit/f3d4034e2a7cee7b1f88c7e6b0d1d69458e1bcf0
- WEBhttps://issues.apache.org/activemq/browse/AMQ-2613
- WEBhttps://issues.apache.org/activemq/browse/AMQ-2625