Impact
The vulnerability allows an attacker to set arbitrary JMS message properties that are copied verbatim into HTTP response headers by the MessageServlet. This can overwrite security headers or inject malicious content, resulting in cross‑site scripting or other header‑based attacks. If exploitable, the attacker could gain JavaScript execution in a victim’s browser or manipulate response headers for malicious purposes.
Affected Systems
Apache ActiveMQ and Apache ActiveMQ Web versions prior to 5.19.7 and before 6.2.6 are affected. Versions 5.19.7 and 6.2.6 contain the fix and deprecate the MessageServlet, which is disabled by default in newer releases.
Risk and Exploitability
The flaw can be triggered by an attacker who can create or modify JMS messages that are served through the web console’s MessageServlet, providing a remote attack vector. The EPSS score of less than 1% indicates a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 6.1 reflects a moderate severity, but the ability to override security headers can facilitate cross‑site scripting or other header‑based attacks, so the risk remains significant.
OpenCVE Enrichment