-
Type:
Bug
-
Status: Resolved
-
Priority:
Blocker
-
Resolution: Fixed
-
Affects Version/s: 5.15.4
-
Component/s: Web Console
-
Labels:None
ActiveMQ 5.15.4 jolokia.jar which has one high severity CVE against it.
Discovered by adding OWASP Dependency check into ActiveMQ pom.xml and running the OWASP report.
CVE-2015-5182 Severity:High CVSS Score: 6.8
allows Cross-site request forgery (CSRF) vulnerability in the jolokia API in A-MQ.
CONFIRM - https://bugzilla.redhat.com/show_bug.cgi?id=1248809 CONFIRM