Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2020-13932

In Apache ActiveMQ Artemis 2.5.0 to 2.13.0, a specially crafted MQTT packet which has an XSS payload as client-id or topic name can exploit this vulnerability. The XSS payload is being injected into the admin console's browser. The XSS payload is triggered in the diagram plugin; queue node and the info section.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.043
EPSS Ranking 89.9%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
References
Products affected by CVE-2020-13932
  • Apache » Artemis » Version: 2.10.0
    cpe:2.3:a:apache:artemis:2.10.0
  • Apache » Artemis » Version: 2.10.1
    cpe:2.3:a:apache:artemis:2.10.1
  • Apache » Artemis » Version: 2.11.0
    cpe:2.3:a:apache:artemis:2.11.0
  • Apache » Artemis » Version: 2.12.0
    cpe:2.3:a:apache:artemis:2.12.0
  • Apache » Artemis » Version: 2.13.0
    cpe:2.3:a:apache:artemis:2.13.0
  • Apache » Artemis » Version: 2.5.0
    cpe:2.3:a:apache:artemis:2.5.0
  • Apache » Artemis » Version: 2.6.0
    cpe:2.3:a:apache:artemis:2.6.0
  • Apache » Artemis » Version: 2.6.1
    cpe:2.3:a:apache:artemis:2.6.1
  • Apache » Artemis » Version: 2.6.2
    cpe:2.3:a:apache:artemis:2.6.2
  • Apache » Artemis » Version: 2.6.3
    cpe:2.3:a:apache:artemis:2.6.3
  • Apache » Artemis » Version: 2.6.4
    cpe:2.3:a:apache:artemis:2.6.4
  • Apache » Artemis » Version: 2.7.0
    cpe:2.3:a:apache:artemis:2.7.0
  • Apache » Artemis » Version: 2.8.0
    cpe:2.3:a:apache:artemis:2.8.0
  • Apache » Artemis » Version: 2.8.1
    cpe:2.3:a:apache:artemis:2.8.1
  • Apache » Artemis » Version: 2.9.0
    cpe:2.3:a:apache:artemis:2.9.0


Contact Us

Shodan ® - All rights reserved