GHSA-3h2h-xqr2-2jp7MediumCVSS 6.1

Cross-site Scripting (XSS) in Apache ActiveMQ Artemis

Published
February 9, 2022
Last Modified
June 15, 2026

🔗 CVE IDs covered (1)

📋 Description

In Apache ActiveMQ Artemis 2.5.0 to 2.13.0, a specially crafted MQTT packet which has an XSS payload as client-id or topic name can exploit this vulnerability. The XSS payload is being injected into the admin console's browser. The XSS payload is triggered in the diagram plugin; queue node and the info section.

🎯 Affected products1

  • maven/org.apache.activemq:apache-artemis:>= 2.5.0, < 2.14.0

🔗 References (9)