GHSA-q9hr-3pg4-3jp4

Suggest an improvement
Source
https://github.com/advisories/GHSA-q9hr-3pg4-3jp4
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-q9hr-3pg4-3jp4/GHSA-q9hr-3pg4-3jp4.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-q9hr-3pg4-3jp4
Aliases
Published
2022-05-13T01:30:05Z
Modified
2024-02-21T05:31:33.245914Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Improper Input Validation in Apache ActiveMQ
Details

Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitrary code via a crafted serialized Java Message Service (JMS) ObjectMessage object.

Database specific
{
    "nvd_published_at": "2016-01-08T19:59:00Z",
    "cwe_ids": [
        "CWE-20"
    ],
    "severity": "CRITICAL",
    "github_reviewed": true,
    "github_reviewed_at": "2022-07-06T20:11:33Z"
}
References

Affected packages

Maven / org.apache.activemq:activemq-client

Package

Name
org.apache.activemq:activemq-client
View open source insights on deps.dev
Purl
pkg:maven/org.apache.activemq/activemq-client

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.0.0
Fixed
5.11.3

Affected versions

5.*

5.8.0
5.9.0
5.9.1
5.10.0
5.10.1
5.10.2
5.11.0
5.11.1
5.11.2

Maven / org.apache.activemq:activemq-client

Package

Name
org.apache.activemq:activemq-client
View open source insights on deps.dev
Purl
pkg:maven/org.apache.activemq/activemq-client

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.12.0
Fixed
5.12.2

Affected versions

5.*

5.12.0
5.12.1