Tracker / CVE-2020-1941
CVE-2020-1941
Medium 6.1
In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in the view that lists the contents of a queue.
Affected products and versions
| apache | activemq · 5.0.0 → 5.15.11 |
|---|---|
| oracle | communications_diameter_signaling_router · 8.0.0 → 8.2.2 |
| oracle | communications_element_manager |
| oracle | communications_session_report_manager |
| oracle | communications_session_route_manager |
| oracle | enterprise_repository |
| oracle | flexcube_private_banking |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.