CVE-2020-13947

MEDIUM6.1EPSS 4.0%

Cross-site scripting (XSS) in Apache ActiveMQ

Published: 2/9/2022Modified: 12/3/2025
Also known as:GHSA-66gw-ch5v-74v8BIT-activemq-2020-13947DEBIAN-CVE-2020-13947

Description

An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the message.jsp page of Apache ActiveMQ versions 5.15.12 through 5.16.0.

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References (14)