Skip to content

Cross-site request forgery in Apache ActiveMQ

Moderate severity GitHub Reviewed Published May 2, 2022 to the GitHub Advisory Database • Updated Dec 21, 2023

Package

maven org.apache.activemq:activemq-parent (Maven)

Affected versions

< 5.3.1

Patched versions

5.3.1

Description

Cross-site request forgery (CSRF) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote attackers to hijack the authentication of unspecified victims for requests that create queues via the JMSDestination parameter in a queue action.

References

Published by the National Vulnerability Database Apr 5, 2010
Published to the GitHub Advisory Database May 2, 2022
Reviewed Dec 21, 2023
Last updated Dec 21, 2023

Severity

Moderate

Weaknesses

CVE ID

CVE-2010-1244

GHSA ID

GHSA-33j4-8vcr-f79v

Source code

Credits

Checking history
See something to contribute? Suggest improvements for this vulnerability.