CVE-2013-3060
Publication date 21 April 2013
Last updated 24 July 2024
Ubuntu priority
The web console in Apache ActiveMQ before 5.8.0 does not require authentication, which allows remote attackers to obtain sensitive information or cause a denial of service via HTTP requests.
Status
Package | Ubuntu Release | Status |
---|---|---|
activemq | ||
14.04 LTS trusty | Not in release | |
Notes
References
Other references
- https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12311210&version=12323282
- https://issues.apache.org/jira/browse/AMQ-4124
- https://fisheye6.atlassian.com/changelog/activemq?cs=1404998
- http://activemq.apache.org/activemq-580-release.html
- http://activemq.2283324.n4.nabble.com/DISCUSS-ActiveMQ-out-of-the-box-Should-not-include-the-demos-tc4658044.html
- https://www.cve.org/CVERecord?id=CVE-2013-3060