OESA-2023-1778
Dashboard / Vulnerabilities / OESA-2023-1778
Summary: activemq security update
Details: The most popular and powerful open source messaging and Integration Patterns server. Security Fix(es): Apache ActiveMQ is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker with network access to a broker to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath. Users are recommended to upgrade to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3, which fixes this issue.(CVE-2023-46604)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2023-1778, https://nvd.nist.gov/vuln/detail/CVE-2023-46604
Affected packages
Package
Name: activemq
Purl: pkg:rpm/openEuler/activemq&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
