In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in the view that lists the contents of a queue.
{ "binaries": [ { "binary_name": "activemq", "binary_version": "5.13.2+dfsg-2ubuntu0.1~esm1" }, { "binary_name": "libactivemq-java", "binary_version": "5.13.2+dfsg-2ubuntu0.1~esm1" } ] }
{ "binaries": [ { "binary_name": "activemq", "binary_version": "5.15.8-2~18.04.1~esm1" }, { "binary_name": "libactivemq-java", "binary_version": "5.15.8-2~18.04.1~esm1" } ] }
{ "binaries": [ { "binary_name": "activemq", "binary_version": "5.15.11-1ubuntu0.1~esm1" }, { "binary_name": "libactivemq-java", "binary_version": "5.15.11-1ubuntu0.1~esm1" } ] }
{ "binaries": [ { "binary_name": "activemq", "binary_version": "5.16.1-1ubuntu0.1" }, { "binary_name": "libactivemq-java", "binary_version": "5.16.1-1ubuntu0.1" } ] }
{ "binaries": [ { "binary_name": "activemq", "binary_version": "5.17.6+dfsg-1" }, { "binary_name": "libactivemq-java", "binary_version": "5.17.6+dfsg-1" } ] }