Information on source package activemq

Available versions

ReleaseVersion
jessie5.6.0+dfsg1-4+deb8u3
jessie (security)5.6.0+dfsg1-4+deb8u2
stretch5.14.3-3
buster5.15.8-2
sid5.15.8-2

Open issues

BugjessiestretchbustersidDescription
CVE-2019-0222fixedvulnerable (no DSA)vulnerable (no DSA)vulnerableIn Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame ca ...
CVE-2018-11775vulnerable (no DSA)vulnerable (no DSA)fixedfixedTLS hostname verification when using the Apache ActiveMQ Client before ...
CVE-2017-15709fixedvulnerable (no DSA)fixedfixedWhen using the OpenWire protocol in ActiveMQ versions 5.14.0 to 5.15.2 ...

Open unimportant issues

BugjessiestretchbustersidDescription
CVE-2018-8006vulnerablevulnerablevulnerablevulnerableAn instance of a cross-site scripting vulnerability was identified to ...
CVE-2016-6810vulnerablefixedfixedfixedIn Apache ActiveMQ 5.x before 5.14.2, an instance of a cross-site scri ...
CVE-2016-0782vulnerablefixedfixedfixedThe administration web console in Apache ActiveMQ 5.x before 5.11.4, 5 ...

Resolved issues

BugDescription
CVE-2016-3088The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 al ...
CVE-2016-0734The web-based administration console in Apache ActiveMQ 5.x before 5.1 ...
CVE-2015-7559DoS in client via shutdown command
CVE-2015-6524The LDAPLoginModule implementation in the Java Authentication and Auth ...
CVE-2015-5254Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that c ...
CVE-2015-1830Directory traversal vulnerability in the fileserver upload/download fu ...
CVE-2014-8110Multiple cross-site scripting (XSS) vulnerabilities in the web based a ...
CVE-2014-3612The LDAPLoginModule implementation in the Java Authentication and Auth ...
CVE-2014-3600XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before ...
CVE-2014-3576The processControlCommand function in broker/TransportConnection.java ...
CVE-2013-3060The web console in Apache ActiveMQ before 5.8.0 does not require authe ...
CVE-2013-1880Cross-site scripting (XSS) vulnerability in the Portfolio publisher se ...
CVE-2013-1879Cross-site scripting (XSS) vulnerability in scheduled.jsp in Apache Ac ...
CVE-2012-6551The default configuration of Apache ActiveMQ before 5.8.0 enables a sa ...
CVE-2012-6092Multiple cross-site scripting (XSS) vulnerabilities in the web demos i ...
CVE-2011-4905Apache ActiveMQ before 5.6.0 allows remote attackers to cause a denial ...

Security announcements

DSA / DLADescription
DLA-913-1activemq - security update
DSA-3524-1activemq - security update
DSA-3524-1activemq - security update
DSA-3330-1activemq - security update
DSA-3330-1activemq - security update

Search for package or bug name: Reporting problems