Junglewise Threat Intelligence

CVE-2020-13932: Apache ActiveMQ Artemis XSS in admin console diagram plugin

CVE-2020-13932 · Severity: medium · CVSS 6.1 · Published 2022-02-09

Technologies: Apache Activemq Artemis. Vendors: Maven, Apache.

Executive brief

Apache ActiveMQ Artemis, a high-performance message broker, is vulnerable to a security flaw in its web-based administration console. An attacker can send a malicious message that, when viewed by an administrator, executes unauthorized scripts in their browser. This could allow an attacker to perform actions on behalf of the administrator or access sensitive session information.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in Apache ActiveMQ Artemis versions 2.5.0 through 2.13.0. The vulnerability is rooted in the improper neutralization of input from MQTT packets, specifically within the 'client-id' or 'topic name' fields. An unauthenticated attacker can send a specially crafted MQTT packet to the broker; when an administrator subsequently uses the web console's diagram plugin to view queue nodes or info sections, the payload is executed in their browser context. This allows for session hijacking or unauthorized administrative actions. The issue is resolved in version 2.14.0.

Affected products

  • Apache ActiveMQ Artemis 2.5.0 to 2.13.0

Timeline

  • 2020-07-20: disclosed: Initial NVD publication
  • 2020-07-20: advisory: Apache security advisory released
  • 2022-02-09: advisory: GitHub Advisory published

References