Remote Cross-Site Scripting in Apache ActiveMQ Artemis
CVE-2020-13932
6.1MEDIUM
What is CVE-2020-13932?
A vulnerability within Apache ActiveMQ Artemis versions 2.5.0 to 2.13.0 allows an attacker to execute remote cross-site scripting (XSS) attacks via specially crafted MQTT packets. These packets can include malicious scripts in the client-id or topic name, which upon processing trigger an injection into the admin console's browser. This exploitation specifically affects the diagram plugin and the info section of queue nodes, posing a security risk to users accessing the web console.
Affected Version(s)
Apache ActiveMQ Artemis Apache ActiveMQ Artemis 2.5.0 to 2.13.0