{"id":"GHSA-hvwm-2624-rp9x","summary":"Apache ActiveMQ web console vulnerable to Cross-site Scripting","details":"An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the queue.jsp page of Apache ActiveMQ versions 5.0.0 to 5.15.5. The root cause of this issue is improper data filtering of the QueueFilter parameter.","aliases":["CVE-2018-8006"],"modified":"2024-03-14T22:16:11.609966Z","published":"2018-10-30T20:48:58Z","database_specific":{"github_reviewed_at":"2020-06-16T21:41:09Z","nvd_published_at":"2018-10-10T14:29:00Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-8006"},{"type":"WEB","url":"https://github.com/apache/activemq/commit/2373aa1"},{"type":"WEB","url":"https://github.com/apache/activemq/commit/d8c80a98212ee5d73a281483a2f8b3f517465f62"},{"type":"PACKAGE","url":"https://github.com/apache/activemq"},{"type":"WEB","url":"https://issues.apache.org/jira/browse/AMQ-6954"},{"type":"WEB","url":"https://lists.apache.org/thread.html/03f91b1fb85686a848cee6b90112cf6059bd1b21b23bacaa11a962e1@%3Cdev.activemq.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/2b5c0039197a4949f29e1e2c9441ab38d242946b966f61c110808bcc@%3Ccommits.activemq.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/3f1e41bc9153936e065ca3094bd89ff8167ad2d39ac0b410f24382d2@%3Cgitbox.activemq.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/a859563f05fbe7c31916b3178c2697165bd9bbf5a65d1cf62aef27d2@%3Ccommits.activemq.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/c0ec53b72b3240b187afb1cf67e4309a9e5f607282010aa196734814@%3Cgitbox.activemq.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/fcbe6ad00f1de142148c20d813fae3765dc4274955e3e2f3ca19ff7b@%3Cdev.activemq.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r946488fb942fd35c6a6e0359f52504a558ed438574a8f14d36d7dcd7@%3Ccommits.activemq.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rb698ed085f79e56146ca24ab359c9ef95846618675ea1ef402e04a6d@%3Ccommits.activemq.apache.org%3E"},{"type":"WEB","url":"https://web.archive.org/web/20200227115717/http://www.securityfocus.com/bid/105156"},{"type":"WEB","url":"http://activemq.apache.org/security-advisories.data/CVE-2018-8006-announcement.txt"}],"affected":[{"package":{"name":"org.apache.activemq:activemq-web-console","ecosystem":"Maven","purl":"pkg:maven/org.apache.activemq/activemq-web-console"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.0.0"},{"fixed":"5.15.6"}]}],"versions":["5.0.0","5.1.0","5.10.0","5.10.1","5.10.2","5.11.0","5.11.1","5.11.2","5.11.3","5.11.4","5.12.0","5.12.1","5.12.2","5.12.3","5.13.0","5.13.1","5.13.2","5.13.3","5.13.4","5.13.5","5.14.0","5.14.1","5.14.2","5.14.3","5.14.4","5.14.5","5.15.0","5.15.1","5.15.2","5.15.3","5.15.4","5.15.5","5.2.0","5.3.0","5.3.1","5.3.2","5.4.0","5.4.1","5.4.2","5.4.3","5.5.0","5.5.1","5.6.0","5.7.0","5.8.0","5.9.0","5.9.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-hvwm-2624-rp9x/GHSA-hvwm-2624-rp9x.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}