Candidate: CVE-2018-8006 PublicDate: 2018-10-10 14:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8006 https://issues.apache.org/jira/browse/AMQ-6954 Description: An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the queue.jsp page of Apache ActiveMQ versions 5.0.0 to 5.15.5. The root cause of this issue is improper data filtering of the QueueFilter parameter. Ubuntu-Description: Notes: sbeattie> admin console not enabled in packaging Bugs: Priority: negligible Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N [6.1 MEDIUM] nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N [6.1 MEDIUM] Patches_activemq: other: https://git-wip-us.apache.org/repos/asf?p=activemq.git;h=d25de5d other: https://git-wip-us.apache.org/repos/asf?p=activemq.git;h=d8c80a9 upstream_activemq: needs-triage precise/esm_activemq: DNE trusty_activemq: ignored (reached end-of-life) trusty/esm_activemq: DNE (trusty was needs-triage) xenial_activemq: ignored (end of standard support, was needs-triage) bionic_activemq: not-affected (5.15.8-2~18.04) cosmic_activemq: not-affected (5.15.8-2~18.04) disco_activemq: not-affected (5.15.8-2) eoan_activemq: not-affected (5.15.8-2) focal_activemq: not-affected (5.15.8-2) groovy_activemq: not-affected (5.15.8-2) hirsute_activemq: not-affected (5.15.8-2) impish_activemq: not-affected (5.15.8-2) jammy_activemq: not-affected (5.15.8-2) devel_activemq: not-affected (5.15.8-2)