Executive brief
Apache ActiveMQ Artemis, a high-performance message broker, is vulnerable to a security flaw in its web-based administration console. An attacker can send a malicious message that, when viewed by an administrator, executes unauthorized scripts in their browser. This could allow an attacker to perform actions on behalf of the administrator or access sensitive session information.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in Apache ActiveMQ Artemis versions 2.5.0 through 2.13.0. The vulnerability is rooted in the improper neutralization of input from MQTT packets, specifically within the 'client-id' or 'topic name' fields. An unauthenticated attacker can send a specially crafted MQTT packet to the broker; when an administrator subsequently uses the web console's diagram plugin to view queue nodes or info sections, the payload is executed in their browser context. This allows for session hijacking or unauthorized administrative actions. The issue is resolved in version 2.14.0.
Affected products
- Apache ActiveMQ Artemis 2.5.0 to 2.13.0
Timeline
- 2020-07-20: disclosed: Initial NVD publication
- 2020-07-20: advisory: Apache security advisory released
- 2022-02-09: advisory: GitHub Advisory published
References
- https://activemq.apache.org/security-advisories.data/CVE-2020-13932-announcement.txt
- https://lists.apache.org/thread.html/r7fcedcc89e5f296b174d6b8c1438c607c30d809c04292e5732d6e4eb@%3Cusers.activemq.apache.org%3E
- https://lists.apache.org/thread.html/rb2fd3bf2dce042e0ab3f3c94c4767c96bb2e7e6737624d63162df36d@%3Ccommits.activemq.apache.org%3E
- https://lists.apache.org/thread.html/rc96ad63f148f784c84ea7f0a178c84a8985c6afccabbcd9847a82088@%3Ccommits.activemq.apache.org%3E
- https://lists.apache.org/thread.html/r7fcedcc89e5f296b174d6b8c1438c607c30d809c04292e5732d6e4eb%40%3Cusers.activemq.apache.org%3E