UBUNTU-CVE-2018-11775
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-11775
UBUNTU-CVE-2018-11775
Summary:
Details: TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vulnerable to a MITM attack between a Java application using the ActiveMQ client and the ActiveMQ server. This is now enabled by default.
References: https://ubuntu.com/security/CVE-2018-11775, http://activemq.apache.org/security-advisories.data/CVE-2018-11775-announcement.txt, https://git-wip-us.apache.org/repos/asf?p=activemq.git;a=commit;h=bde7097fb8173cf871827df7811b3865679b963d, https://git-wip-us.apache.org/repos/asf?p=activemq.git;a=commit;h=02971a40e281713a8397d3a1809c164b594abfbb, https://www.cve.org/CVERecord?id=CVE-2018-11775, https://ubuntu.com/security/notices/USN-6910-1
Affected packages
Package
Name: activemq
Purl: pkg:deb/ubuntu/[email protected]+dfsg-2ubuntu0.1~esm1?arch=source&distro=esm-apps/xenial
Affected ranges
Type: ECOSYSTEM
Events:
