[CONF] Apache ActiveMQ > Security Advisories

2019-03-27 Thread Dejan Bosanac (Confluence)
Title: Message Title



 
 
 
There's 2 new edits on this page 
 
 
 
 
 
 
  
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Security Advisories 
 
 
  
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

 
 
 
 
Dejan Bosanac edited this page 
 
 
  
 
 

 
 
 
  
 
 
  
 
 
  
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Here's what changed: 
 
 
 
 
 
 
 
 
 
 
 Apache ActiveMQ  2019  
 
 CVE-2019-0222 - Corrupt MQTT frame can cause broker shutdown  
 2018 
 
  CVE-2018-8006 - ActiveMQ Web Console - Cross-Site Scripting  
  CVE-2017-15709 - Information Leak   
  CVE-2018-11775 - Missing TLS Hostname Verification
 ...  
 
 
  
 
 
  
 
 
  
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Go to page history 
 
 
  
 
 
  
 
 
  
 
 
  
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
View page 
 
 
  
 
 
  
 
 
  
 
 
  
 
 
 
 
 
 
 
 
 
 
Stop watching space
• 
 
 
 
 
 
 
Manage notifications 
 
 
 
 
 
 
 
 
 
 
  
 
 
This message was sent by Atlassian Confluence 6.14.2  
 
 
  
 
 
 
 
 
 
 
 
 




[CONF] Apache ActiveMQ > Security Advisories

2018-10-10 Thread Christopher L. Shannon (Confluence)
Title: Message Title



 
 
 
There's 1 new edit on this page 
 
 
 
 
 
 
  
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Security Advisories 
 
 
  
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

 
 
 
 
Christopher L. Shannon edited this page 
 
 
  
 
 

 
 
 
  
 
 
  
 
 
  
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Here's what changed: 
 
 
 
 
 
 
 
 
 
 
 Apache ActiveMQ 2018 
 
  CVE-2018-8006 - ActiveMQ Web Console - Cross-Site Scripting   
  CVE-2017-15709 - Information Leak   
  CVE-2018-11775 - Missing TLS Hostname Verification
 ...  
 
 
  
 
 
  
 
 
  
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Go to page history 
 
 
  
 
 
  
 
 
  
 
 
  
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
View page 
 
 
  
 
 
  
 
 
  
 
 
  
 
 
 
 
 
 
 
 
 
 
Stop watching space
• 
 
 
 
 
 
 
Manage notifications 
 
 
 
 
 
 
 
 
 
 
  
 
 
This message was sent by Atlassian Confluence 6.9.0  
 
 
  
 
 
 
 
 
 
 
 
 




[CONF] Apache ActiveMQ > Security Advisories

2018-09-10 Thread Christopher L. Shannon (Confluence)
Title: Message Title



 
 
 
There's 1 new edit on this page 
 
 
 
 
 
 
  
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Security Advisories 
 
 
  
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

 
 
 
 
Christopher L. Shannon edited this page 
 
 
  
 
 

 
 
 
  
 
 
  
 
 
  
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Here's what changed: 
 
 
 
 
 
 
 
 
 
 
 Apache ActiveMQ 2018 
 
  CVE-2017-15709 - Information Leak   
  CVE-2018-11775 - Missing TLS Hostname Verification
 2017 
 
  CVE-2015-7559 - DoS in client via shutdown command   
 2016 
 
 CVE-2016-6810 - ActiveMQ Web Console - Cross-Site Scripting 
 CVE-2016-0734 - ActiveMQ Web Console - Clickjacking 
 CVE-2016-0782 - ActiveMQ Web Console - Cross-Site Scripting 
 CVE-2016-3088 - ActiveMQ Fileserver web application vulnerabilities 
 2015 
 
 CVE-2015-5254 - Unsafe deserialization in ActiveMQ 
 CVE-2015-1830 - Path traversal leading to unauthenticated RCE in ActiveMQ  
 2014 
 
 CVE-2014-3576 - Remote Unauthenticated Shutdown of Broker (DoS) 
 CVE-2014-3600 - Apache ActiveMQ XXE with XPath selectors 
 CVE-2014-3612 - ActiveMQ JAAS: LDAPLoginModule allows empty password authentication and Wildcard Interpretation 
 CVE-2014-8110 - ActiveMQ Web Console - Cross-Site Scripting
  ActiveMQ Apollo   2014  
 
  CVE-2014-3579 - ActiveMQ Apollo XXE with XPath selectors  
      
 
 
  
 
 
  
 
 
  
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Go to page history 
 
 
  
 
 
  
 
 
  
 
 
  
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
View page 
 
 
  
 
 
  
 
 
  
 
 
  
 
 
 
 
 
 
 
 
 
 
Stop watching space
• 
 
 
 
 
 
 
Manage notifications 
 
 
 
 
 
 
 
 
 
 
  
 
 
This message was sent by Atlassian Confluence 6.9.0  
 
 
  
 
 
 
 
 
 
 
 
 




[CONF] Apache ActiveMQ > Security Advisories

2018-09-10 Thread Christopher L. Shannon (Confluence)
Title: Message Title



 
 
 
There's 1 new edit on this page 
 
 
 
 
 
 
  
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Security Advisories 
 
 
  
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

 
 
 
 
Christopher L. Shannon edited this page 
 
 
  
 
 

 
 
 
  
 
 
  
 
 
  
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Here's what changed: 
 
 
 
 
 
 
 
 
 
 
 ... 
 
  CVE-2017-15709 - Information Leak   
  CVE-2018-11775 - Missing TLS Hostname Verification 
 2017 
 
  CVE-2015-7559 - DoS in client via shutdown command   
 ...  
 
 
  
 
 
  
 
 
  
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Go to page history 
 
 
  
 
 
  
 
 
  
 
 
  
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
View page 
 
 
  
 
 
  
 
 
  
 
 
  
 
 
 
 
 
 
 
 
 
 
Stop watching space
• 
 
 
 
 
 
 
Manage notifications 
 
 
 
 
 
 
 
 
 
 
  
 
 
This message was sent by Atlassian Confluence 6.9.0  
 
 
  
 
 
 
 
 
 
 
 
 




[CONF] Apache ActiveMQ > Security Advisories

2018-02-13 Thread Christopher L. Shannon (Confluence)
Title: Message Title



 
 
 
 
 
 
 

Christopher L. Shannon edited a page 
 
 
  
 
 
 
 
 
 
 
  
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Security Advisories 
 
 
  
 
 
 
 
 
 
 Apache ActiveMQ  2018  
 
  CVE-2017-15709 - Information Leak   
  2017  
 
  CVE-2015-7559 - DoS in client via shutdown command   
 ...  
 
 
  
 
 
 
 
 
 
 
 
 
 

View page
• 
 
 
 
 
 
 

Like 
 
 
  
 
 
  
 
 
  
 
 
  
 
 
 
 
 
 
 
 
 
 
Stop watching space
• 
 
 
 
 
 
 
Manage notifications 
 
 
 
 
 
 
 
 
 
 
  
 
 
This message was sent by Atlassian Confluence 5.8.17  
 
 
  
 
 
 
 
 
 
 
 
 




[CONF] Apache ActiveMQ > Security Advisories

2018-02-13 Thread Christopher L. Shannon (Confluence)
Title: Message Title



 
 
 
 
 
 
 

Christopher L. Shannon edited a page 
 
 
  
 
 
 
 
 
 
 
  
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Security Advisories 
 
 
  
 
 
 
 
 
 
 Apache ActiveMQ  2018  ...  2017  ...   2017  
 
  CVE-2015-7559 - DoS in client via shutdown command   
 ...  
 
 
  
 
 
 
 
 
 
 
 
 
 

View page
• 
 
 
 
 
 
 

Like 
 
 
  
 
 
  
 
 
  
 
 
  
 
 
 
 
 
 
 
 
 
 
Stop watching space
• 
 
 
 
 
 
 
Manage notifications 
 
 
 
 
 
 
 
 
 
 
  
 
 
This message was sent by Atlassian Confluence 5.8.17  
 
 
  
 
 
 
 
 
 
 
 
 




[CONF] Apache ActiveMQ > Security Advisories

2018-02-12 Thread Christopher L. Shannon (Confluence)
Title: Message Title



 
 
 
 
 
 
 

Christopher L. Shannon edited a page 
 
 
  
 
 
 
 
 
 
 
  
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Security Advisories 
 
 
  
 
 
 
 
 
 
 Apache ActiveMQ  2018  
 
  CVE-2017-15709 - Information Leak   
  2017  
 
  CVE-2015-7559 - DoS in client via shutdown command   
 ...  
 
 
  
 
 
 
 
 
 
 
 
 
 

View page
• 
 
 
 
 
 
 

Like 
 
 
  
 
 
  
 
 
  
 
 
  
 
 
 
 
 
 
 
 
 
 
Stop watching space
• 
 
 
 
 
 
 
Manage notifications 
 
 
 
 
 
 
 
 
 
 
  
 
 
This message was sent by Atlassian Confluence 5.8.17  
 
 
  
 
 
 
 
 
 
 
 
 




[CONF] Apache ActiveMQ > Security Advisories

2017-04-24 Thread Dejan Bosanac (Confluence)
Title: Message Title



 
 
 
 
 
 
 

Dejan Bosanac edited a page 
 
 
  
 
 
 
 
 
 
 
  
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Security Advisories 
 
 
  
 
 
 
 
 
 
 ... 
 
  CVE-2015-7559 - DoS in client via shutdown command   
     2016 
 
 CVE-2016-6810 - ActiveMQ Web Console - Cross-Site Scripting 
 CVE-2016-0734 - ActiveMQ Web Console - Clickjacking 
 CVE-2016-0782 - ActiveMQ Web Console - Cross-Site Scripting 
 CVE-2016-3088 - ActiveMQ Fileserver web application vulnerabilities 
 ...  
 
 
  
 
 
 
 
 
 
 
 
 
 

View page
• 
 
 
 
 
 
 

Like 
 
 
  
 
 
  
 
 
  
 
 
  
 
 
 
 
 
 
 
 
 
 
Stop watching space
• 
 
 
 
 
 
 
Manage notifications 
 
 
 
 
 
 
 
 
 
 
  
 
 
This message was sent by Atlassian Confluence 5.8.4  
 
 
  
 
 
 
 
 
 
 
 
 




[CONF] Apache ActiveMQ > Security Advisories

2017-04-24 Thread Dejan Bosanac (Confluence)
Title: Message Title



 
 
 
 
 
 
 

Dejan Bosanac edited a page 
 
 
  
 
 
 
 
 
 
 
  
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Security Advisories 
 
 
  
 
 
 
 
 
 
 Apache ActiveMQ  2017  
 
  CVE-2015-7559 - DoS in client via shutdown command   
     2016 
 
 CVE-2016-6810 - ActiveMQ Web Console - Cross-Site Scripting 
 CVE-2016-0734 - ActiveMQ Web Console - Clickjacking 
 CVE-2016-0782 - ActiveMQ Web Console - Cross-Site Scripting 
 CVE-2016-3088 - ActiveMQ Fileserver web application vulnerabilities 
 ...  
 
 
  
 
 
 
 
 
 
 
 
 
 

View page
• 
 
 
 
 
 
 

Like 
 
 
  
 
 
  
 
 
  
 
 
  
 
 
 
 
 
 
 
 
 
 
Stop watching space
• 
 
 
 
 
 
 
Manage notifications 
 
 
 
 
 
 
 
 
 
 
  
 
 
This message was sent by Atlassian Confluence 5.8.4  
 
 
  
 
 
 
 
 
 
 
 
 




[CONF] Apache ActiveMQ > Security Advisories

2016-12-09 Thread Christopher L. Shannon (Confluence)
Title: Message Title



 
 
 
 
 
 
 

Christopher L. Shannon edited a page 
 
 
  
 
 
 
 
 
 
 
  
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Security Advisories 
 
 
  
 
 
 
 
 
 
 Apache ActiveMQ 2016 
 
 CVE-2016-6810 - ActiveMQ Web Console - Cross-Site Scripting  
 CVE-2016-0734 - ActiveMQ Web Console - Clickjacking 
 CVE-2016-0782 - ActiveMQ Web Console - Cross-Site Scripting 
 CVE-2016-3088 - ActiveMQ Fileserver web application vulnerabilities 
 ...  
 
 
  
 
 
 
 
 
 
 
 
 
 

View page
• 
 
 
 
 
 
 

Like 
 
 
  
 
 
  
 
 
  
 
 
  
 
 
 
 
 
 
 
 
 
 
Stop watching space
• 
 
 
 
 
 
 
Manage notifications 
 
 
 
 
 
 
 
 
 
 
  
 
 
This message was sent by Atlassian Confluence 5.8.4  
 
 
  
 
 
 
 
 
 
 
 
 




[CONF] Apache ActiveMQ > Security Advisories

2016-05-23 Thread Dejan Bosanac (Confluence)
Title: Message Title



 
 
 
 
 
 
 

Dejan Bosanac edited a page 
 
 
  
 
 
 
 
 
 
 
  
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Security Advisories 
 
 
  
 
 
 
 
 
 
 ... 
 
 CVE-2016-0734 - ActiveMQ Web Console - Clickjacking 
 CVE-2016-0782 - ActiveMQ Web Console - Cross-Site Scripting 
 CVE-2016-3088 - ActiveMQ Fileserver web application vulnerabilities  
 2015 
 
 CVE-2015-5254 - Unsafe deserialization in ActiveMQ 
 CVE-2015-1830 - Path traversal leading to unauthenticated RCE in ActiveMQ  
 ...  
 
 
  
 
 
 
 
 
 
 
 
 
 

View page
• 
 
 
 
 
 
 

Like 
 
 
  
 
 
  
 
 
  
 
 
  
 
 
 
 
 
 
 
 
 
 
Stop watching space
• 
 
 
 
 
 
 
Manage notifications 
 
 
 
 
 
 
 
 
 
 
  
 
 
This message was sent by Atlassian Confluence 5.8.4  
 
 
  
 
 
 
 
 
 
 
 
 




[CONF] Apache ActiveMQ > Security Advisories

2016-03-10 Thread Christopher L. Shannon (Confluence)
Title: Message Title



 
 
 
 
 
 
 

Christopher L. Shannon edited a page 
 
 
  
 
 
 
 
 
 
 
  
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Security Advisories 
 
 
  
 
 
 
 
 
 
 Apache ActiveMQ  2016  
 
 CVE-2016-0734 - ActiveMQ Web Console - Clickjacking  
 CVE-2016-0782 - ActiveMQ Web Console - Cross-Site Scripting  
 2015 
 
 CVE-2015-5254 - Unsafe deserialization in ActiveMQ 
 CVE-2015-1830 - Path traversal leading to unauthenticated RCE in ActiveMQ  
 ...  
 
 
  
 
 
 
 
 
 
 
 
 
 

View page
• 
 
 
 
 
 
 

Like 
 
 
  
 
 
  
 
 
  
 
 
  
 
 
 
 
 
 
 
 
 
 
Stop watching space
• 
 
 
 
 
 
 
Manage notifications 
 
 
 
 
 
 
 
 
 
 
  
 
 
This message was sent by Atlassian Confluence 5.8.4  
 
 
  
 
 
 
 
 
 
 
 
 




[CONF] Apache ActiveMQ > Security Advisories

2015-12-08 Thread Dejan Bosanac (Confluence)
Title: Message Title



 
 
 
 
 
 
 

Dejan Bosanac edited a page 
 
 
  
 
 
 
 
 
 
 
  
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Security Advisories 
 
 
  
 
 
 
 
 
 
 Apache ActiveMQ 2015 
 
 CVE-2015-5254 - Unsafe deserialization in ActiveMQ  
 
 
 CVE-2015-1830 - Path traversal leading to unauthenticated RCE in ActiveMQ  
 ...  
 
 
  
 
 
 
 
 
 
 
 
 
 

View page
• 
 
 
 
 
 
 

Like 
 
 
  
 
 
  
 
 
  
 
 
  
 
 
 
 
 
 
 
 
 
 
Stop watching space
• 
 
 
 
 
 
 
Manage notifications 
 
 
 
 
 
 
 
 
 
 
  
 
 
This message was sent by Atlassian Confluence 5.8.4  
 
 
  
 
 
 
 
 
 
 
 
 




[CONF] Apache ActiveMQ > Security Advisories

2015-12-08 Thread Dejan Bosanac (Confluence)
Title: Message Title



 
 
 
 
 
 
 

Dejan Bosanac edited a page 
 
 
  
 
 
 
 
 
 
 
  
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Security Advisories 
 
 
  
 
 
 
 
 
 
 Apache ActiveMQ 2015 
 
 CVE-2015-5254 - Unsafe deserialization in ActiveMQ 
 CVE-2015-1830 - Path traversal leading to unauthenticated RCE in ActiveMQ  
 ...  
 
 
  
 
 
 
 
 
 
 
 
 
 

View page
• 
 
 
 
 
 
 

Like 
 
 
  
 
 
  
 
 
  
 
 
  
 
 
 
 
 
 
 
 
 
 
Stop watching space
• 
 
 
 
 
 
 
Manage notifications 
 
 
 
 
 
 
 
 
 
 
  
 
 
This message was sent by Atlassian Confluence 5.8.4  
 
 
  
 
 
 
 
 
 
 
 
 




[CONF] Apache ActiveMQ > Security Advisories

2015-12-08 Thread Dejan Bosanac (Confluence)
Title: Message Title



 
 
 
 
 
 
 

Dejan Bosanac edited a page 
 
 
  
 
 
 
 
 
 
 
  
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Security Advisories 
 
 
  
 
 
 
 
 
 
 Apache ActiveMQ 2015 
 
 CVE-2015-5254 - Unsafe deserialization in ActiveMQ 
 CVE-2015-1830 - Path traversal leading to unauthenticated RCE in ActiveMQ  
 2014 
 
 CVE-2014-3576 - Remote Unauthenticated Shutdown of Broker (DoS) 
 CVE-2014-3600 - Apache ActiveMQ XXE with XPath selectors 
 CVE-2014-3612 - ActiveMQ JAAS: LDAPLoginModule allows empty password authentication and Wildcard Interpretation 
 CVE-2014-8110 - ActiveMQ Web Console - Cross-Site Scripting
  ActiveMQ Apollo   2014  
 
  CVE-2014-3579 - ActiveMQ Apollo XXE with XPath selectors  
      
 
 
  
 
 
 
 
 
 
 
 
 
 

View page
• 
 
 
 
 
 
 

Like 
 
 
  
 
 
  
 
 
  
 
 
  
 
 
 
 
 
 
 
 
 
 
Stop watching space
• 
 
 
 
 
 
 
Manage notifications 
 
 
 
 
 
 
 
 
 
 
  
 
 
This message was sent by Atlassian Confluence 5.8.4  
 
 
  
 
 
 
 
 
 
 
 
 




[CONF] Apache ActiveMQ > Security Advisories

2015-11-07 Thread Christopher L. Shannon (Confluence)
Title: Message Title



 
 
 
 
 
 
 

Christopher L. Shannon edited a page 
 
 
  
 
 
 
 
 
 
 
  
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Security Advisories 
 
 
  
 
 
 
 
 
 
 ... 
 
 CVE-2015-1830 - Path traversal leading to unauthenticated RCE in ActiveMQ  
 2014 
 
 CVE-2014-3576 - Remote Unauthenticated Shutdown of Broker (Dos)  
 CVE-2014-3600 - Apache ActiveMQ XXE with XPath selectors 
 CVE-2014-3612 - ActiveMQ JAAS: LDAPLoginModule allows empty password authentication and Wildcard Interpretation 
 CVE-2014-8110 - ActiveMQ Web Console - Cross-Site Scripting
 ...  
 
 
  
 
 
 
 
 
 
 
 
 
 

View page
• 
 
 
 
 
 
 

Like 
 
 
  
 
 
  
 
 
  
 
 
  
 
 
 
 
 
 
 
 
 
 
Stop watching space
• 
 
 
 
 
 
 
Manage notifications 
 
 
 
 
 
 
 
 
 
 
  
 
 
This message was sent by Atlassian Confluence 5.8.4  
 
 
  
 
 
 
 
 
 
 
 
 




[CONF] Apache ActiveMQ > Security Advisories

2015-11-07 Thread Christopher L. Shannon (Confluence)
Title: Message Title



 
 
 
 
 
 
 

Christopher L. Shannon edited a page 
 
 
  
 
 
 
 
 
 
 
  
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Security Advisories 
 
 
  
 
 
 
 
 
 
 ... 
 
 CVE-2014-3576 - Remote Unauthenticated Shutdown of Broker (DosDoS) 
 CVE-2014-3600 - Apache ActiveMQ XXE with XPath selectors 
 CVE-2014-3612 - ActiveMQ JAAS: LDAPLoginModule allows empty password authentication and Wildcard Interpretation 
 CVE-2014-8110 - ActiveMQ Web Console - Cross-Site Scripting
 ...  
 
 
  
 
 
 
 
 
 
 
 
 
 

View page
• 
 
 
 
 
 
 

Like 
 
 
  
 
 
  
 
 
  
 
 
  
 
 
 
 
 
 
 
 
 
 
Stop watching space
• 
 
 
 
 
 
 
Manage notifications 
 
 
 
 
 
 
 
 
 
 
  
 
 
This message was sent by Atlassian Confluence 5.8.4  
 
 
  
 
 
 
 
 
 
 
 
 




[CONF] Apache ActiveMQ Security Advisories

2015-08-25 Thread Dejan Bosanac (Confluence)
Title: Message Title



 
 
 
 
 
 
 

Dejan Bosanac edited a page 
 
 
  
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Security Advisories 
 
 
  
 
 
 
 
 
 
 ... 
 
 CVE-2015-1830 - Path traversal leading to unauthenticated RCE in ActiveMQActiveMQ  
 2014 
 
 CVE-2014-3600 -Apache ActiveMQ XXE with XPath selectors 
 CVE-2014-3612 -ActiveMQ JAAS: LDAPLoginModule allows empty password authentication and Wildcard Interpretation 
 CVE-2014-8110 -ActiveMQ Web Console - Cross-Site Scripting
 ...  
 
 
  
 
 
 
 
 
 
 
 
 
 

View page
• 
 
 
 
 
 
 

Like 
 
 
  
 
 
  
 
 
 
 
 
  
 
 
 
 
 
 
 
 
 
 
Stop watching space
• 
 
 
 
 
 
 
Manage notifications 
 
 
 
 
 
 
 
 
 
 
  
 
 
This message was sent by Atlassian Confluence 5.8.4  
 
 
  
 
 
 
 
 
 
 
 
 




[CONF] Apache ActiveMQ Security Advisories

2015-08-17 Thread Dejan Bosanac (Confluence)
Title: Message Title



 
 
 
 
 
 
 

Dejan Bosanac edited a page 
 
 
  
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Security Advisories 
 
 
  
 
 
 
 
 
 
 Apache ActiveMQ  2015  
 
 CVE-2015-1830 - Path traversal leading to unauthenticated RCE in ActiveMQ  
 2014 
 
 CVE-2014-3600 -Apache ActiveMQ XXE with XPath selectors 
 CVE-2014-3612 -ActiveMQ JAAS: LDAPLoginModule allows empty password authentication and Wildcard Interpretation 
 CVE-2014-8110 -ActiveMQ Web Console - Cross-Site Scripting
  ActiveMQ Apollo   2014  
 
 CVE-2014-3579 -ActiveMQ Apollo XXE with XPath selectors  
 ...  
 
 
  
 
 
 
 
 
 
 
 
 
 

View page
• 
 
 
 
 
 
 

Like 
 
 
  
 
 
  
 
 
 
 
 
  
 
 
 
 
 
 
 
 
 
 
Stop watching space
• 
 
 
 
 
 
 
Manage notifications 
 
 
 
 
 
 
 
 
 
 
  
 
 
This message was sent by Atlassian Confluence 5.8.4