#VU42892 Cross-site scripting in ActiveMQ - CVE-2012-6092
Published: April 22, 2013 / Updated: January 15, 2021
ActiveMQ
Apache Foundation
Description
Vulnerability allows a remote attacker to perform Cross-site scripting attacks.
An input validation error exists in the web demos in Apache ActiveMQ before 5.8.0 when processing (1) the refresh parameter to PortfolioPublishServlet.java (aka demo/portfolioPublish or Market Data Publisher), or vectors involving (2) debug logs or (3) subscribe messages in webapp/websocket/chat.js. NOTE: AMQ-4124 is covered by CVE-2012-6551. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in victim's browser in security context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Remediation
External links
- http://activemq.apache.org/activemq-580-release.html
- http://rhn.redhat.com/errata/RHSA-2013-1029.html
- http://www.securityfocus.com/bid/59400
- https://fisheye6.atlassian.com/changelog/activemq?cs=1399577
- https://issues.apache.org/jira/browse/AMQ-4115
- https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12311210&version=12323282