Launch Week Day 1: Announcing Security Design Review
MEDIUM 4.9 Maven

Improper Input Validation and Missing Authentication for Critical Function in Apache ActiveMQ

GHSA-jvpp-hxjj-5ccc · CVE-2015-7559

Published · Modified

Description

It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker logged into a compromised broker could use this flaw to achieve denial of service on a connected client.

Ready to move

Start Securing

Free, no credit card | First findings in minutes