Nixpkgs Security Tracker

Login with GitHub

Suggestions search

With package: activemq

Found 1 matching suggestions

View:
Compact
Detailed
updated 3 weeks, 2 days ago by @anthonyroussel Activity log
  • Created automatic suggestion
  • @anthonyroussel dismissed
It was found that the Apache ActiveMQ client before 5.14.5 …

It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker logged into a compromised broker could use this flaw to achieve denial of service on a connected client.

Affected products

ActiveMQ
  • ==5.15.5

Matching in nixpkgs

Package maintainers

Old CVE, fixed with ActiveMQ 5.14.5
Upstream commit: https://github.com/apache/activemq/commit/b8fc78e
https://issues.apache.org/jira/browse/AMQ-6470