In Apache ActiveMQ Artemis prior to 2.24.0, an attacker could show malicious content and/or redirect users to a malicious URL in the web console by using HTML in the name of an address or queue.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-6543 In Apache ActiveMQ Artemis prior to 2.24.0, an attacker could show malicious content and/or redirect users to a malicious URL in the web console by using HTML in the name of an address or queue.
Github GHSA Github GHSA GHSA-cv6r-h2fm-pvrp HTML Injection in ActiveMQ Artemis Web Console
Fixes

Solution

No solution given by the vendor.


Workaround

Upgrade to Apache ActiveMQ Artemis 2.24.0.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2024-08-03T09:36:44.249Z

Reserved: 2022-07-06T00:00:00

Link: CVE-2022-35278

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-08-23T15:15:11.247

Modified: 2024-11-21T07:11:01.790

Link: CVE-2022-35278

cve-icon Redhat

Severity : Important

Publid Date: 2022-08-18T00:00:00Z

Links: CVE-2022-35278 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses