GHSA-33j4-8vcr-f79v

Suggest an improvement
Source
https://github.com/advisories/GHSA-33j4-8vcr-f79v
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-33j4-8vcr-f79v/GHSA-33j4-8vcr-f79v.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-33j4-8vcr-f79v
Aliases
  • CVE-2010-1244
Published
2022-05-02T06:20:35Z
Modified
2024-11-28T05:31:30.288383Z
Summary
Cross-site request forgery in Apache ActiveMQ
Details

Cross-site request forgery (CSRF) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote attackers to hijack the authentication of unspecified victims for requests that create queues via the JMSDestination parameter in a queue action.

Database specific
{
    "nvd_published_at": "2010-04-05T16:30:00Z",
    "cwe_ids": [
        "CWE-352"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2023-12-21T18:48:02Z"
}
References

Affected packages

Maven / org.apache.activemq:activemq-parent

Package

Name
org.apache.activemq:activemq-parent
View open source insights on deps.dev
Purl
pkg:maven/org.apache.activemq/activemq-parent

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.3.1

Affected versions

4.*

4.1.1
4.1.2

5.*

5.0.0
5.1.0
5.2.0
5.3.0