Description
In Apache ActiveMQ Artemis prior to 2.24.0, an attacker could show malicious content and/or redirect users to a malicious URL in the web console by using HTML in the name of an address or queue.
Published: 2022-08-23
Score: 6.1 Medium
EPSS: 7.9% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Workaround

Upgrade to Apache ActiveMQ Artemis 2.24.0.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-6543 In Apache ActiveMQ Artemis prior to 2.24.0, an attacker could show malicious content and/or redirect users to a malicious URL in the web console by using HTML in the name of an address or queue.
Github GHSA Github GHSA GHSA-cv6r-h2fm-pvrp HTML Injection in ActiveMQ Artemis Web Console
History

No history.

Subscriptions

Apache Activemq Artemis
Netapp Active Iq Unified Manager Oncommand Workflow Automation
Redhat Amq Broker
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2024-08-03T09:36:44.249Z

Reserved: 2022-07-06T00:00:00.000Z

Link: CVE-2022-35278

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-08-23T15:15:11.247

Modified: 2024-11-21T07:11:01.790

Link: CVE-2022-35278

cve-icon Redhat

Severity : Important

Publid Date: 2022-08-18T00:00:00Z

Links: CVE-2022-35278 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses