GHSA-jvpp-hxjj-5ccc
Dashboard / Vulnerabilities / GHSA-jvpp-hxjj-5ccc
Summary: Improper Input Validation and Missing Authentication for Critical Function in Apache ActiveMQ
Details: It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker logged into a compromised broker could use this flaw to achieve denial of service on a connected client.
References: https://nvd.nist.gov/vuln/detail/CVE-2015-7559, https://github.com/apache/activemq/commit/b8fc78ec6c367cbe2a40a674eaec64ac3d7d1ec, https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2015-7559, https://github.com/apache/activemq, https://issues.apache.org/jira/browse/AMQ-6470
Affected packages
Package
Name: org.apache.activemq:activemq-client
Purl: pkg:maven/org.apache.activemq/activemq-client
Affected ranges
Type: ECOSYSTEM
Events:
