CVE-2020-13947
MEDIUM6.1EPSS 4.0%Cross-site scripting (XSS) in Apache ActiveMQ
發布日:2022/2/9修改日:2026/4/28
描述
An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the message.jsp page of Apache ActiveMQ versions 5.15.12 through 5.16.0.
受影響套件(3)
- Bitnami/activemqfrom 0, < 5.15.14, >= 5.16.0, < 5.16.1
- Debian/activemqfrom 0, < 5.16.1-1
- Maven/org.apache.activemq:activemq-parent>= 5.16.0, < 5.16.1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
參考連結(14)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2020-13947
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2020-13947
- PATCHhttps://github.com/apache/activemq
- WEBhttp://activemq.apache.org/security-advisories.data/CVE-2020-13947-announcement.txt
- WEBhttps://github.com/apache/activemq/commit/177eb71c52069712bcc9fe14c70e079cc2671a80
- WEBhttps://github.com/apache/activemq/compare/activemq-5.16.0...activemq-5.16.1
- WEBhttps://lists.apache.org/thread.html/r021c490028f61c8b6f7e38efb98e61693b0cbb6b99b02238c6fc7d66@%3Ccommits.activemq.apache.org%3E
- WEBhttps://lists.apache.org/thread.html/r021c490028f61c8b6f7e38efb98e61693b0cbb6b99b02238c6fc7d66%40%3Ccommits.activemq.apache.org%3E
- WEBhttps://lists.apache.org/thread.html/ra66791f1f2b59fa651a81cec5202acdfbf34c2154fc0ff200301cc1c@%3Cdev.activemq.apache.org%3E
- WEBhttps://lists.apache.org/thread.html/ra66791f1f2b59fa651a81cec5202acdfbf34c2154fc0ff200301cc1c@%3Cusers.activemq.apache.org%3E
- WEBhttps://lists.apache.org/thread.html/ra66791f1f2b59fa651a81cec5202acdfbf34c2154fc0ff200301cc1c%40%3Cdev.activemq.apache.org%3E
- WEBhttps://lists.apache.org/thread.html/ra66791f1f2b59fa651a81cec5202acdfbf34c2154fc0ff200301cc1c%40%3Cusers.activemq.apache.org%3E
- WEBhttps://www.oracle.com/security-alerts/cpuApr2021.html
- WEBhttps://www.oracle.com/security-alerts/cpuoct2021.html