CVE-2022-35278

MEDIUM

Apache ActiveMQ Artemis < 2.24.0 - Cross-Site Scripting via Address or Queue Name

Title source: llm
STIX 2.1

Description

In Apache ActiveMQ Artemis prior to 2.24.0, an attacker could show malicious content and/or redirect users to a malicious URL in the web console by using HTML in the name of an address or queue.

References (2)

Core 2

Scores

CVSS v3 6.1
EPSS 0.0786
EPSS Percentile 92.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-80 CWE-79
Status published
Products (4)
apache/activemq_artemis < 2.24.0
netapp/active_iq_unified_manager
netapp/oncommand_workflow_automation
org.apache.activemq/artemis-server 0 - 2.24.0Maven
Published Aug 23, 2022
Tracked Since Feb 18, 2026